A European technology company hires a software engineer on a research visa. The engineer is a national of a country subject to targeted EU controls. On day one, the engineer is granted access to the company's controlled dual-use technology repository. No physical export occurs. No customs declaration is filed. Yet, under EU export-control rules, a transfer of controlled technology may already have taken place – and the company may have violated its obligations before the first line of code was read.
Deemed exports and technology transfer under the EU regime refer to the transmission of controlled dual-use technology or software to a foreign national – through oral briefing, system access, or written disclosure – without that technology physically leaving the EU. As of April 2026, the governing instrument is the EU Dual-Use Regulation, which replaced its predecessor and extended controls explicitly to intangible transfers of technology. The key question is whether the technology is listed, whether a licence is required, and whether an exemption applies to the specific transfer.
This guide walks through the governing authority, the transfer test, cross-regime comparison with the US and UK positions, the main risk flags, and the practical steps a compliance team should take before granting access.
What does the EU Dual-Use Regulation actually control?
The EU Dual-Use Regulation controls the export, brokering, transit, and – critically – the intangible transfer of dual-use items, which include goods, software, and technology that have both civil and military applications. Technology is controlled when it is specifically required for the development, production, or use of a listed item. Software is controlled when it contains, embeds, or directly enables such technology.
The regulation is administered jointly by the European Commission and the competent authorities of each EU Member State. In practice, licensing decisions rest at the national level: a German exporter applies to the Bundesamt für Wirtschaft und Ausfuhrkontrolle, a French company to the Direction générale du Trésor, and so on. The EU General Export Authorisation provides a standing permission for certain low-risk transfers to specified destinations, but it does not cover all technology categories and it does not eliminate the obligation to classify the item first.
What makes this regime demanding for modern businesses is the breadth of "technology transfer." The regulation does not restrict its application to physical shipments. Oral briefings at a conference, access credentials for a cloud-hosted repository, a slide deck transmitted by encrypted email – each can constitute an intangible transfer if the underlying technology is listed. In our experience, many businesses do not discover this until a staff-screening or onboarding review surfaces a gap.
How is a deemed export triggered in the EU context?
A deemed export is triggered when controlled technology or software is made accessible – through any medium – to a person who will transfer it outside the EU, or who is a national of a country subject to specific controls, even if that person is physically present within the EU at the moment of access. The trigger is access, not geography.
The analysis proceeds in three steps. First, does the technology appear on the EU Common Military List or the EU Dual-Use List (the Annex to the Dual-Use Regulation)? If it does not, ordinary export-control rules do not apply, though broader trade-restriction or sanctions obligations may still be relevant. Second, is the recipient a national of, or an entity connected to, a destination or person for which the regulation imposes controls? Third, does an exemption or authorisation cover the transfer – for instance, the general authorisation for intra-company transfers, or a national general export authorisation?
The second step is where the deemed-export concept has its sharpest practical bite. EU rules do not contain a single, codified "deemed export" definition that mirrors the US terminology precisely, but the intangible-transfer controls in the Dual-Use Regulation produce the same practical result: access by the wrong person to listed technology is a regulated event regardless of where that person sits. Compliance teams should treat this operationally as a deemed-export analysis even if the regulation frames it in different language.
Have you mapped every point at which a foreign national could access your controlled technology – including remote desktop sessions, shared drives, and training materials?
Step 1 – Classify the technology before any access is granted
Classification is the foundation. Before granting any person access to technology that could plausibly fall on the EU Dual-Use List, the item must be assessed against the relevant control parameters: category, group (equipment, test, production, software, or technology), and the specific technical parameters in the list entry.
Classification is not a one-time exercise. Technology evolves, list entries are periodically updated, and a product that fell outside controls two years ago may now be caught by a revised entry or by a new catch-all control triggered by end-use concerns. Businesses that operate a static classification library – produced once and never revisited – carry ongoing exposure.
We regularly advise clients on building a living classification register: a record that logs each item's classification rationale, the date of review, the list version reviewed against, and the person responsible. That record serves two purposes. It demonstrates due diligence to a competent authority in the event of a query. And it forces a periodic review discipline that catches changes before they become violations.
For software and source code specifically, the classification question requires attention to whether the software is "in the public domain" (a defined concept under the regulation that, if satisfied, takes the item out of control) or whether it meets the parameters for a listed entry. The public-domain analysis is technical and fact-specific; a generic "it's open-source" conclusion is not sufficient.
Step 2 – Screen the recipient and identify the destination
Once the technology is classified as controlled, the next step is screening the recipient against the relevant lists and assessing the destination country. EU controls apply to transfers to destinations subject to arms embargoes (where the stricter prohibition governs), to destinations listed under the Dual-Use Regulation's catch-all provisions, and to any person appearing on the EU Consolidated List of persons subject to restrictive measures.
For a deemed-export analysis the "destination" is the nationality of the individual recipient and the country where any onward transfer is likely. A researcher holding a passport from a destination subject to EU arms embargo controls and accessing controlled production-technology presents a different risk profile from a researcher holding a passport from a country covered by a Union General Export Authorisation. The screening obligation is therefore layered: the person, the entity they work for, the destination they represent, and any end-use concern that the technology's nature raises.
In a recent matter, a manufacturing business in an EU Member State engaged an external consultant to assist with a product-development programme. The consultant was a national of a country subject to targeted controls. The technology involved was listed under the Dual-Use Regulation. The business had screened the consultant against financial-sanctions lists – that check came back clear – but had not run an export-control assessment of the access. We were instructed to scope the apparent transfer, advise on whether voluntary disclosure was appropriate, and assist with the licence application for the ongoing engagement. The matter underscored a persistent pattern: sanctions screening and export-control screening are separate disciplines and cannot be substituted for one another.
Step 3 – Determine whether a licence or authorisation is required
Where the technology is listed and the recipient or destination falls outside any applicable exemption, a specific licence from the competent national authority is required before access is granted. In the EU, specific licences are issued by the relevant Member State authority; there is no single EU-wide specific-licence issuing body for dual-use items.
The application must set out the nature of the technology, the classification basis, the identity of the recipient, the purpose of the transfer, and the end-use assurances available. Processing times vary between Member States and between categories of technology; a well-prepared application with complete supporting documentation moves faster than one that requires repeated supplementation. In our experience, the most common cause of delay is incomplete classification evidence submitted with the initial filing.
For intra-company transfers – for instance, making controlled technology available to employees or subsidiaries in third countries – the Dual-Use Regulation provides specific authorisations in certain circumstances. These are not automatic; the conditions must be assessed carefully, documentation requirements must be met, and the company must be registered where the regime requires registration. An assumption that intra-company transfers are always exempt is one of the most frequent misconceptions we encounter.
The position above covers the standard case. Your facts – the specific technology, the recipient's nationality, the purpose, the Member State of application, and the destination – change the analysis considerably. If you are uncertain whether a licence is required, or if an application has been refused, early advice preserves options that narrow with time.
To discuss a licence application, classify a technology, or assess an ongoing programme, contact Calder & Vance at info@caldervance.com.
How does the EU position compare with the US and UK regimes?
The EU, US, and UK regimes each control intangible technology transfer, but they differ in structure, terminology, and scope – and those differences produce real divergence in how a cross-border business must manage its obligations.
Under the US Export Administration Regulations (the EAR), administered by the Bureau of Industry and Security (BIS), a deemed export occurs when controlled technology is released to a foreign national in the United States. The EAR uses the term "deemed export" explicitly and links the foreign national's deemed destination to their most recent country of citizenship. The classification uses an Export Control Classification Number (ECCN – a code on the Commerce Control List that identifies the control parameters and licensing requirements for an item) and the control reason determines the licence requirement. BIS licence applications are made centrally to a single federal authority.
The UK position, administered by the Export Control Joint Unit (ECJU) under the Export Control Order, also catches intangible transfers. The UK has maintained its dual-use list broadly aligned with the pre-Brexit EU list but has since diverged in certain areas, particularly following updates to the Wassenaar Arrangement. A business transferring controlled technology to a foreign national in the UK must apply to the ECJU for a specific open individual export licence or a standard individual export licence, depending on the category and destination. OFSI, the UK financial-sanctions authority, has no role in export-control licensing, though a transaction may engage both OFSI and ECJU obligations in parallel.
The practical cross-regime implication is this: a business with operations in the EU, the US, and the UK may face three separate licensing obligations for what looks like a single personnel or technology-access decision. The strictest prohibition governs each jurisdiction independently; compliance with the EU Dual-Use Regulation does not discharge the EAR obligation, and vice versa. We have acted for businesses that resolved the EU licensing question carefully but had not mapped the US or UK dimension at all – and discovered the gap only when a regulator made an enquiry. Does your compliance programme treat all three regimes as independent obligations?
For detailed guidance on the US BIS and EAR deemed-export obligations, see our related service on deemed exports and technology transfer under BIS and the EAR.
Common risk flags and when to involve counsel
Several patterns consistently indicate elevated deemed-export risk. Recognising them early allows a business to seek a licence or restructure access before a potential violation occurs.
- Unrestricted repository access on onboarding. New employees, contractors, and visiting researchers are granted blanket access to all technical systems as a default. Where those systems contain listed technology, the access decision is an export-control decision – not merely an IT-administration one.
- Foreign nationals in R&D or production roles whose nationality has not been assessed against the relevant destination controls.
- Cloud-based collaboration platforms shared with international partners, particularly where the platform is hosted outside the EU and access controls are not jurisdiction-specific.
- Academic or research collaborations that involve sharing pre-publication results, models, or datasets without a prior classification review.
- Mergers and acquisitions where the target holds controlled technology and the post-close integration plan includes staff with access from foreign-national employees of the acquirer.
- Intra-group transfers to subsidiaries or affiliates in third countries, treated as internal matters without a licence assessment.
Counsel should be involved whenever a classification produces a listed result, whenever a specific licence application is required, whenever a potential violation is identified (at which point the question of voluntary self-disclosure – a report to the competent authority ahead of any enforcement enquiry – must be considered), and whenever the cross-regime picture is uncertain. Early involvement is not a counsel-generation tactic; it is a practical recognition that the competent national authority's attitude to an apparent breach is materially better when the business has identified the issue, stopped the conduct, and presented a clear account of what happened.
If a transfer has already occurred without a required licence, or if a compliance review has surfaced a gap, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss your situation confidentially.
A common misconception: "we are not exporting anything"
The most persistent myth in this area is that export-control obligations apply only when goods cross a physical border. Businesses operating entirely within the EU – manufacturing, research, and technology companies that never ship hardware outside the Member States – sometimes conclude that the Dual-Use Regulation is simply not relevant to their day-to-day operations.
That conclusion is incorrect. The EU Dual-Use Regulation applies to intangible transfers. A company that develops controlled encryption software and employs a team that includes foreign nationals from countries subject to controls has export-control obligations with respect to those employees' access to the technology. The absence of a physical shipment is irrelevant. The absence of a customs declaration is irrelevant. The fact that the technology never left the building is irrelevant. What matters is whether controlled technology was made accessible to a person whose nationality or destination triggers a control.
A second misconception is that the public-domain exemption is broad enough to cover most software. In practice, the exemption requires a careful technical assessment. Software that has been published online does not automatically qualify; the conditions under the regulation are specific and have been interpreted narrowly in enforcement contexts. A business that relies on a blanket public-domain claim without having conducted the requisite assessment is exposed.
Related practices
- Deemed exports under BIS and the EAR – US counterpart analysis: ECCN classification, deemed-export licensing, and BIS enforcement.
- Deemed exports and technology transfer – EU: advanced issues – catch-all controls, end-use certificates, and post-shipment verification.
- Deemed exports and OFAC sanctions – where export-control and financial-sanctions obligations intersect.