A technology company hires a visiting researcher from abroad. The researcher will work alongside the engineering team, reviewing technical specifications and software source code for a controlled item. No goods leave the facility. No export licence is on the file. That oversight may already constitute an unlicensed export under the Export Administration Regulations (the EAR, administered by the Bureau of Industry and Security, BIS) – a "deemed export" that carries the same legal exposure as shipping controlled hardware to a foreign destination without authorisation.
Under the EAR, a deemed export occurs when controlled technology or source code is released to a foreign national inside the United States; that release is treated as an export to the person's most recently held country of nationality. The governing authority is BIS, operating under the Export Control Reform Act and IEEPA. The consequences of an unlicensed deemed export can include significant civil penalties, denial of export privileges, and criminal referral – all without a single item leaving US territory.
As of April 2026, deemed exports remain one of the highest-frequency gaps identified in BIS compliance reviews of technology companies, universities, and research institutions. This guide sets out the classification analysis, the licensing decision, the cross-regime comparison, and the programme controls that reduce exposure.
Step 1: Understand the legal basis and who administers deemed exports
BIS administers the EAR under authority derived from the Export Control Reform Act and IEEPA; any release of EAR-controlled technology or source code to a foreign national in the United States is regulated as an export to that person's country of most recent nationality. The rule applies to in-person access, remote access, and oral disclosure.
The instrument is the Commerce Control List (CCL), which assigns an Export Control Classification Number (ECCN) to each controlled item, technology, or software. An ECCN specifies which countries trigger a licence requirement and for what reasons – national security, nuclear non-proliferation, missile technology, or other listed grounds. Items not on the CCL are classified as EAR99 and generally do not require a licence for a deemed export, although exclusions exist for embargoed countries and denied persons.
Two categories of persons are relevant. BIS maintains the Entity List (entities subject to heightened licence requirements) and the Denied Persons List (individuals and firms against whom export privileges have been denied). A foreign national who is employed by or affiliated with an Entity List entity triggers a separate licence analysis, irrespective of where the technology sits on the CCL.
The position above covers the standard analysis. Your facts – the ECCN, the foreign national's nationality, the relevant controls, and the presence of any licence exception – determine whether a specific release is lawful without authorisation. The deemed-export question is not resolved by the absence of physical shipment.
For a detailed assessment of your classification and licensing position, contact Calder & Vance at info@caldervance.com.
Step 2: Classify the technology or source code before any release
Classification is the first and most consequential step: technology and source code released to a foreign national must be classified against the CCL before access is granted, and that classification must be documented. An incorrect or absent classification is itself an aggravating factor in a BIS enforcement review.
The classification process follows a structured sequence. First, identify the item by its technical parameters – performance characteristics, materials, functions, and outputs. Second, review each relevant category and entry on the CCL for a match. Third, confirm the reason for control (NS, NP, MT, or others) that attaches to the ECCN. Fourth, assess whether a licence exception in the EAR is available.
Several licence exceptions are relevant to deemed exports. The Technology and Software – Unrestricted (TSU) exception covers certain publicly available technology and software. The Licence Exception Technology and Software under Restriction (TSR) is available for releases to nationals of certain countries for items controlled only for national-security reasons, subject to conditions. Neither exception is universal. Both have country-scope limitations that are defined by the applicable country regime and the ECCN's reason-for-control designation.
In our experience, the most common error at this stage is not the classification itself but the failure to connect the ECCN to the foreign national's nationality. A technology team may correctly identify the ECCN and then fail to apply it to every national in the room. Have you run a nationality check on every person who will have access – not only the lead researcher?
Step 3: Screen the foreign national and apply the nationality analysis
Once the technology is classified, the second axis of the deemed-export test is the nationality of the person receiving access. BIS applies the most recent citizenship or permanent residence rule: if a foreign national holds citizenship in more than one country, or has held permanent residency in more than one country, the analysis must cover all such countries.
The screening obligation runs in parallel with the ECCN analysis. Every foreign national who will receive access to controlled technology must be screened against the BIS consolidated lists – the Entity List and the Denied Persons List – and against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). An OFAC screening hit on a foreign national may block the transaction independently of the BIS analysis, even where BIS would not require a licence.
This intersection is important. In our cross-border practice, we regularly advise technology companies that have correctly worked through the ECCN analysis but have not built OFAC screening into the deemed-export process. OFAC controls apply to any transaction with a designated person regardless of whether the BIS licence requirement is met or waived. The two regimes operate independently; satisfying one does not satisfy the other.
Beyond listed-person screening, consider the employer and the affiliation. A researcher employed by a university that is on the Entity List may require a BIS licence for access to items as low as EAR99 in some circumstances. The affiliation question is distinct from the nationality question and must be addressed separately in the screening workflow.
Step 4: Determine the licence requirement and apply for authorisation where needed
Where no licence exception covers the proposed release, the business must either obtain a BIS licence before releasing the technology or restructure the access arrangement to remove the foreign national from the controlled information. Proceeding without one or the other is an apparent violation.
A BIS specific-licence application for a deemed export is submitted through the SNAP-R system to BIS's Office of Exporter Services. The application identifies the technology by ECCN, the end-user by name and nationality, the proposed use, and the safeguards in place. BIS may consult with other agencies – including the Department of State and the Department of Defense – before issuing a decision. Processing times vary by commodity and by the reviewing agencies involved; verify the current expected timeline with BIS or with counsel before committing to a project start date.
Licence conditions are common. BIS may authorise the release subject to record-keeping requirements, end-use assurances, and restrictions on further transfer. Breach of a condition can itself constitute a violation independent of the underlying transaction.
If a transaction has already been flagged, or a release has already occurred without a licence, an early assessment can preserve options that narrow with time. A voluntary self-disclosure (VSD – a voluntary self-disclosure to BIS of an apparent violation) may be appropriate. BIS's enforcement posture treats a timely, well-prepared VSD as a mitigating factor. Write to info@caldervance.com for a confidential review.
How does the BIS deemed-export rule compare with EU and UK technology-transfer controls?
The BIS deemed-export rule has no direct equivalent in the EU or UK export-control regimes; both the EU and UK regimes focus on the physical export or electronic transfer of technology across a border, rather than on the nationality of the recipient inside the exporting country. That difference in architecture is material for multinational businesses that manage a single compliance programme across jurisdictions.
Under the EU dual-use rules (Council Regulation 2021/821 as amended), a licence is required for the transfer of controlled technology to a destination outside the EU, including by electronic means. An oral briefing or software access granted to a foreign national who is physically present in the EU is generally not caught as a deemed export in the same way as BIS applies the rule – though the position depends on the item, the end-user, and the transaction structure. The EU General Court has addressed the scope of technology-transfer controls in a line of annulment cases; experience before that court confirms that the analysis is fact-specific and that legal advice is warranted for any grey-area access arrangement.
Under the UK Export Control Order, administered by ECJU, a similar principle applies: the focus is on transfer to a destination, including electronic transfer, rather than on a deemed-export-by-nationality test. OFSI's financial-sanctions regime is a separate layer; it does not impose technology-transfer controls but may block a transaction with a designated person independently.
The practical consequence for a multinational is that a foreign national working at a US facility on controlled technology may require a BIS deemed-export licence, while the same person working at the company's EU or UK facility would not trigger the same nationality-based analysis. That asymmetry requires jurisdiction-specific controls rather than a unified global procedure. Where the stricter prohibition governs, compliance with the more permissive regime is not sufficient.
For a detailed comparison of the EU technology-transfer rules, see our guide at EU deemed-export and technology-transfer controls. For a further comparative analysis, see also our supplementary EU technology-transfer briefing.
What are the risk flags that escalate a deemed-export matter?
Several fact patterns escalate deemed-export risk from a licensing question to an enforcement matter requiring immediate attention. Recognising them early shapes the response.
- Access already granted without a classification review. If controlled technology has been released to foreign nationals without a prior ECCN analysis, the business should assess whether an apparent violation has occurred before taking any further steps.
- Multiple nationalities in a single access event. A group meeting, a training session, or a shared code repository can constitute simultaneous releases to nationals of multiple countries, each requiring its own analysis.
- An employer affiliation with the Entity List. Access by a researcher employed by or affiliated with an Entity List entity may require a licence even for items that would not otherwise require one for that nationality.
- Dual-nationality and recent change of citizenship. A foreign national who has recently naturalised in a third country may not have disclosed that change. Periodic recertification of nationality data is a recognised programme control.
- Remote access arrangements. Cloud access, remote desktop sessions, and shared collaboration platforms can constitute a release under the EAR. The physical location of the server is not determinative; the nationality of the person accessing the technology is.
- Post-acquisition integration of technology teams. M&A transactions that bring together technology teams without a deemed-export review of combined access arrangements are a recurring source of apparent violations identified by BIS.
In our experience, the post-acquisition gap is the most consistently under-addressed. Integration timelines create pressure to merge systems and personnel before compliance reviews are complete. We regularly advise acquirers to build a deemed-export assessment into the pre-close due-diligence work and again into the Day 1 integration checklist.
Step 5: Build and maintain a deemed-export compliance programme
A one-time classification review is not sufficient. Sustained compliance requires a documented programme that covers classification, screening, access controls, record-keeping, and periodic review. BIS's enforcement guidance identifies the absence of a written compliance programme as an aggravating factor in penalty determinations.
The five elements of an effective deemed-export programme are: (1) a written policy that covers technology access by foreign nationals; (2) a pre-access classification and screening workflow applied consistently to all facilities, remote systems, and project-based access; (3) a licence-and-exception management register that tracks authorisations, conditions, and expiry dates; (4) record-keeping that meets the EAR's retention standard for export-related documentation; and (5) periodic internal review – at least annually – and a process for updating the programme when the CCL or BIS guidance changes.
Record-keeping under the EAR requires that export-related documents be maintained for a defined period. The EAR prescribes a specific retention period for records relating to export transactions; verify the current requirement before designing your retention schedule, as the applicable period is subject to regulatory change.
A common myth is that academic and research institutions are exempt from the deemed-export rules because of the publicly available information exclusion and the fundamental-research exclusion. Neither exclusion is categorical. The fundamental-research exclusion applies to basic and applied research in science and engineering where the results are ordinarily published and shared broadly, but it does not cover proprietary research, export-controlled sponsor requirements, or access by researchers who are subject to publication restrictions. Institutions that rely on this exclusion without a detailed review of the terms and conditions of each programme regularly find that the exclusion does not apply as expected.
To stress-test your deemed-export screening and compliance programme, reach our team at info@caldervance.com.
Related practices
- Deemed Export & Technology Transfer (BIS/EAR) – Service – end-to-end advisory on classification, licensing, and programme design for US deemed-export matters
- EU Deemed Export and Technology Transfer Controls – how EU dual-use rules treat technology access and cross-border transfer obligations