A US-headquartered technology group hires a researcher on a two-year contract. The researcher holds citizenship from a country subject to comprehensive OFAC sanctions. On their first day they receive access to a shared technical repository containing controlled encryption algorithms. Has the company just made an unlicensed export? The answer, under the deemed-export doctrine, is almost certainly yes – and the exposure does not require a shipping label or a customs form.
As of April 2026, deemed exports and technology transfer under OFAC remain one of the least-understood intersections of US sanctions and export-control law. OFAC treats the release of technology to a foreign national on US soil as a deemed export to their home country. Where that country is subject to a comprehensive OFAC sanctions programme, the release is prohibited without authorisation, regardless of whether the information ever leaves the building.
This guide works through the deemed-export doctrine step by step: how to identify a risk, how the test operates, where OFAC and BIS diverge, and what a business should do to manage its exposure before a breach occurs.
Step 1: Understand what a deemed export is and why OFAC cares
A deemed export is a release of controlled technology or source code to a foreign national inside the United States that is treated, in law, as an export to that person's home country. OFAC's authority derives from the International Emergency Economic Powers Act (IEEPA), which grants the President – and through delegation, OFAC – broad powers to prohibit transactions with countries or persons designated under a national emergency.
The intersection with deemed exports arises because OFAC's country-based prohibitions do not distinguish between physical shipments and informational transfers. If releasing technology to a foreign national constitutes a service, a transfer of value, or a dealing in property to or on behalf of a sanctioned party, OFAC's prohibitions apply. The analysis is not purely academic: enforcement actions in adjacent areas have established that informational transfers can constitute prohibited transactions under IEEPA-based programmes.
What makes this difficult in practice is the layering of two separate regulatory regimes. The Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS), have an explicit and detailed deemed-export rule tied to Export Control Classification Numbers. OFAC's approach is different in structure and origin but can produce overlapping – and sometimes stricter – prohibitions. In our experience, businesses that focus exclusively on BIS classification miss a distinct and serious exposure sitting underneath the OFAC layer.
Step 2: Identify which OFAC programmes are triggered by a technology transfer
Not every OFAC programme raises a deemed-export problem: the question is whether the specific programme in play prohibits services, technology transfers, or dealings with nationals of the relevant country. Comprehensive country-based sanctions programmes are the primary risk zone. Targeted, list-based programmes – where the prohibition runs to specific designated persons rather than to an entire country's nationals – raise a different and narrower question.
The key distinction sits between comprehensive and targeted programmes. Under a comprehensive programme, the prohibition is broad enough to capture the release of technology to nationals of that country, absent an applicable general or specific licence. Under a targeted programme, the question is whether the recipient appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or is an entity owned 50 percent or more by a blocked person under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked).
What should a compliance team do at this stage? Run both checks in parallel. First, determine whether the foreign national holds citizenship or permanent residence in a country subject to a comprehensive OFAC programme. Second, screen the individual's name against the SDN List and the Consolidated Sanctions List. Third, check whether their employer or sponsor is itself a blocked entity. Each check is independent; a clean result on one does not cure exposure on another.
The position above covers the standard case. Your facts – the counterparty's nationality, their access to specific technology categories, the OFAC programme in play, and the licensing position – change the analysis materially. For an initial assessment, contact Calder & Vance at info@caldervance.com.
Step 3: Map the technology and assess the transfer
Mapping the technology in question is the step most businesses handle poorly. The temptation is to classify it under the EAR, confirm it holds a low-level or EAR99 classification, and conclude no licence is required. That logic is sound for BIS purposes but does not resolve the OFAC question.
Under OFAC's analysis, the relevant question is not whether the item has a particular ECCN (Export Control Classification Number under the US Commerce Control List) but whether the transfer constitutes a prohibited dealing with a country or person within the scope of the applicable programme. EAR99 items can still be caught. So can oral briefings, demonstrations, and software demonstrations given in a meeting room. The breadth of "technology" for OFAC purposes is effectively co-extensive with anything that has economic value and can be transferred.
A practical mapping exercise proceeds in four steps:
- Identify every category of technical information to which the individual will have access – source code, engineering drawings, proprietary process documentation, and research data all count.
- Determine whether any element was developed using controlled US-origin technology, even if the item itself is not independently listed.
- Confirm whether access is incidental (background technology they will encounter) or specific (targeted technology transfer integral to their role).
- Document the mapping, because the documentation is itself a component of a defensible compliance posture if OFAC ever reviews the matter.
The mapping exercise should be reviewed by legal counsel with OFAC experience, not delegated entirely to the technical team. In our experience, the technical team's instinct is to classify narrowly. The sanctions analysis requires a broader read.
How does the OFAC analysis differ from the BIS deemed-export rule?
The OFAC and BIS deemed-export rules share a common policy objective – controlling the transfer of sensitive technology to foreign nationals whose home country is a concern – but they operate through distinct legal mechanisms, and the differences are operationally significant.
Under the EAR, BIS has a specific and codified deemed-export rule. The rule applies to controlled items identified by ECCN on the Commerce Control List (CCL). The trigger for a BIS deemed-export licence requirement is: (a) the item has an ECCN with a control reason applicable to the recipient's country, and (b) a licence exception does not apply. For items classified EAR99, the BIS deemed-export rule does not apply. The application process is a formal licence request to BIS, and the licensing decision turns on the specific technology and the specific country.
OFAC's approach is different in three respects. First, OFAC does not operate a separate "deemed-export licence" application as such. Authorisation comes through a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) or a general licence (a standing authorisation that permits a defined category of transactions without a separate application) under the applicable sanctions programme. Second, there is no EAR99 safe harbour within OFAC's analysis: the question is about the programme's prohibition on dealings with the country or person, not about the item's classification. Third, the legal basis is IEEPA and the relevant country-based executive orders rather than the Export Control Reform Act that undergirds the EAR.
The practical consequence is that a business may need two separate licences – one from BIS under the EAR and one from OFAC under the relevant sanctions programme – for the same technology transfer. Neither licence substitutes for the other. In our cross-border practice, we regularly advise businesses that were unaware they needed both, having received a BIS deemed-export licence and assumed the matter was resolved.
A further divergence concerns the citizenship-versus-nationality question. BIS looks to the most recent non-US citizenship of the individual. OFAC's analysis looks to whether the transfer constitutes a prohibited dealing, which can turn on nationality, country of birth, or the individual's connection to a sanctioned party, depending on the programme. A researcher who has naturalised as a US citizen may clear the BIS test but still raise OFAC questions under a specific programme's provisions. That scenario is more common than most compliance teams expect.
If a transaction has already been flagged by an OFAC screening process, or a licence application has encountered difficulty, an early review preserves options that narrow with delay. For a confidential review of a potential breach, contact us at info@caldervance.com.
Step 4: Apply the authorisation analysis – licences, exceptions, and general licences
Identifying a potential prohibition is only half the analysis. The next question is whether an authorisation exists that permits the transfer to proceed lawfully.
Under OFAC's programmes, authorisations fall into two categories. General licences are published and publicly available; they authorise defined categories of transactions without a separate application. If a general licence covers the contemplated transfer, the business may proceed – but must ensure the transaction falls strictly within the licence's terms, and must retain records consistent with any reporting obligations attached to the general licence.
Where no general licence applies, a specific licence is required. The application is submitted to OFAC directly. The process requires a detailed statement of the applicant, the recipient, the technology in question, and the purpose of the transfer. OFAC reviews applications on a case-by-case basis. There is no guaranteed outcome, and in our experience the processing time for specific licence applications varies considerably depending on the programme and the complexity of the request.
Businesses should also examine whether the technology transfer falls within an available EAR licence exception, but – as noted above – an EAR exception does not cure an OFAC prohibition. The authorisation analysis for OFAC must be conducted on OFAC's own terms.
A common error at this stage is to assume that because the individual is physically present in the United States on a lawful visa, a deemed-export analysis is unnecessary. That assumption is wrong. Visa status determines immigration admissibility; it does not resolve the sanctions and export-control analysis. Compliance counsel and immigration counsel need to work from the same facts, and neither should assume the other has covered the sanctions piece.
Step 5: Build the ongoing compliance programme for technology-access risk
A one-time pre-hire review is insufficient. Technology-access risk is dynamic: foreign nationals' home-country circumstances can change, sanctions programmes are added, modified, and occasionally terminated, and internal access privileges expand over time without a corresponding re-screening trigger. An effective programme needs to be ongoing, not episodic.
The five structural elements of a defensible programme are these:
- Access controls mapped to the sanctions analysis. System permissions should reflect the outcome of the deemed-export assessment, not merely the individual's employment role. Where access to a particular dataset would trigger an OFAC prohibition, that access should be restricted pending authorisation.
- Periodic re-screening. The SDN List and the applicable country programmes change. A re-screening cycle should be built into the employment or contractor relationship, with a defined trigger for review whenever OFAC announces changes to the relevant programme.
- A documented decision log. Each deemed-export assessment, each conclusion, and the basis for that conclusion should be recorded. In the event of an OFAC inquiry, documentation is the primary evidence of a good-faith compliance effort.
- A clear escalation path. Personnel who identify a potential issue – a new hire's nationality, a change in programme scope, an access request that looks unusual – must have a defined route to compliance counsel. Informal escalation paths fail in practice.
- Training calibrated to role. HR, IT, research directors, and legal need different training, because each function sees a different slice of the risk. A single annual training session delivered identically to all staff does not achieve the required coverage.
Where does this programme sit within a broader sanctions compliance framework? OFAC has published detailed guidance on the elements it expects to see in a sanctions compliance programme. That guidance is not legally binding, but it is the baseline OFAC uses when evaluating whether a company acted with reasonable care. A programme that tracks those elements substantially reduces the risk of a finding of reckless disregard or wilful violation – two aggravating factors that affect penalty exposure.
Risk flags: when to involve counsel immediately
Most deemed-export questions can be managed through a well-designed internal process. Some cannot. The following situations require immediate involvement of qualified sanctions and export-control counsel.
First: you discover that a foreign national already employed has had unrestricted access to controlled technology and no prior deemed-export assessment was conducted. This is a potential apparent violation. The question of whether to make a VSD (voluntary self-disclosure to a regulator) is a legal question, not a compliance-programme question, and it should not be decided without counsel. A VSD that is poorly scoped or badly timed can create more exposure than it resolves.
Second: OFAC changes the scope of a comprehensive programme in a way that captures a nationality or category of persons that was previously outside it. The window between the effective date of the change and your discovery of its implications can be very short. Early counsel involvement is the only way to preserve the options available in that window.
Third: a licence application is denied or is issued with conditions that are difficult to satisfy operationally. OFAC's denial is an administrative decision; it is not necessarily the end of the road. There are routes – including reconsideration and, in certain circumstances, judicial review – that are only available if pursued promptly and correctly.
Fourth: the matter touches more than one jurisdiction. A UK employer transferring technology to a researcher who holds both a country-of-concern nationality and a connection to a designated entity raises questions under OFSI's financial-sanctions regime in addition to OFAC. The EU, through the relevant Council regulations, has its own ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) analysis that is distinct from OFAC's 50 percent rule. In cross-border situations, the stricter prohibition governs each aspect of the transaction.
A myth worth addressing directly: "if the technology isn't defence-related or classified, OFAC won't care." This is incorrect. OFAC's country-based comprehensive programmes are not limited to military or dual-use technology. A software tool with purely commercial applications can still be a prohibited transfer if the recipient is a national of a comprehensively sanctioned country and no authorisation applies. The classification of the item under the EAR does not determine whether OFAC's prohibition is engaged.
Related practices
- Export controls and dual-use – BIS/EAR deemed-export service – classification, licence requirements, and exception analysis under the EAR.
- Deemed-export risk guide (part 3) – deep-dive on the licensing application process under OFAC programmes.