The wider regime · 5.2

Export control, named and not advised on

Export control, named and not advised on. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see OECD AI Principles.

What this entry does

Names the regimes and stops

Technical data of the kind a defence manufacturer holds may be subject to export control, under regimes administered separately from anything discussed elsewhere on this site. The two best known in the United States are the regulations covering defence articles and services and those covering dual-use items.

This entry exists because export control constrains the same architectural decisions that security compliance constrains, and because suppliers regularly assume that satisfying one addresses the other. It does not.

What this entry will not do is tell you what applies to you. Export control determinations turn on the specific item, its technical characteristics and its classification, and getting one wrong carries consequences of a different order from a compliance finding. That is work for qualified export counsel and nobody else.

Why it appears on a security site

Three decisions where the regimes collide

Where data is stored and processed. A choice of cloud region or provider made for security reasons may have export implications.

Who administers your systems. Support and administration performed by people of certain nationalities, wherever they are physically located, can engage export rules through the concept of releasing controlled data to a foreign person.

Who your suppliers are and where they sit. Including your own supply chain and any offshore support arrangement.

Each of those is a decision a security programme makes routinely, and each can be made in a way that satisfies the security requirement and creates an export problem.

The common assumption

Compliance with one is not compliance with the other

The security requirement asks you to protect information. Export control asks who may receive it. A perfectly protected system that gives access to a person export rules say may not receive the data satisfies the first and breaches the second.

They are answered by different people using different documents and neither answer substitutes for the other.

What to do

Four practical steps, none of them advice

Establish whether your technical data is subject to control, with counsel. Ensure the person running the security programme knows the answer. Include the question in your change process, so that a decision about a cloud region or a support arrangement triggers it. And keep the determination documented.

The failure mode is not usually a bad decision; it is a decision taken by somebody who did not know the question existed.

Marking

Where it shows up in daily work

Controlled technical data is typically marked, and the marking travels with the file. A file governance system that preserves and acts on markings is doing something export counsel will care about, and one that strips them is creating a problem.

This is one of the few places where a security product genuinely touches export compliance, and it is worth raising with any vendor.

The statement

Nothing in this entry is advice

It names two regimes and describes where they intersect with decisions discussed elsewhere on this site. It states no rule, offers no classification and should not be relied on for any determination.

If you handle technical data for defence programmes and have never had an export assessment, that is the conversation to have, and it is not with us.

Also

Elsewhere in the wider regime