Select your language
Blog
Blog description
When Digital Access Becomes an Export: OFAC, BIS, EAR, and ITAR Risks in Cloud Systems and Remote Work
An export-control violation may begin with an email, repository permission, cloud backup, support ticket, or remote login, not a physical shipment. The EAR and ITAR regulate digital transmissions and foreign-person access, while their encryption provisions offer protection only when every condition is satisfied.
Export controls are no longer confined to the shipping dock. A drawing attached to an email, source code displayed during screen sharing, technical data placed in a support ticket, or a remote login to a restricted repository may transmit controlled material across borders or release it to an unauthorized foreign person inside the United States.
Recent enforcement activity makes that risk concrete. In February 2024, the U.S. Department of State reached a $51 million administrative settlement with Boeing to resolve 199 charged violations of the International Traffic in Arms Regulations (ITAR). The proposed charging letter described foreign-person employees and contractors at overseas facilities who downloaded ITAR-controlled technical data from a digital repository on more than 100 occasions. It also described an employee forwarding controlled documents by email to two foreign-person employees in India. Boeing voluntarily disclosed the matters, and the charges were resolved by agreement rather than adjudicated in court.
The practical lesson is straightforward: export compliance must follow the data and the user – not merely the device, network, or office.
Digital access can be an export
Under the Export Administration Regulations (EAR):

A release can occur through visual inspection or an oral or written exchange. The ITAR likewise treats sending a defense article out of the United States, releasing technical data to a foreign person in the United States, and performing a defense service for a foreign person as export. Its definition of technical data focuses on the substance of information, including certain information required for the design, development, production, operation, repair, testing, or maintenance of defense articles — not the file format or communication channel.
Accordingly, a design pasted into chat, code viewed through a remote desktop, diagnostic information added to a service request, or instructions discussed during a video call may require the same analysis as a formal file transfer. The result depends on the applicable regulatory jurisdiction and classification, the recipient, nationality or immigration status where relevant, physical location, destination, end user, end use, and the scope of any license, agreement, exception, or exclusion.
OFAC Sanctions and BIS Export Controls for Cloud Access and Remote Work
BIS and OFAC administer separate but potentially overlapping regulatory regimes.

Even an EAR99 item or a transaction that would not ordinarily require a license based solely on its destination may be restricted when a prohibited end use or a party appearing on the Entity List, Denied Persons List, Unverified List, or Military End-User List is involved.

OFAC restrictions may also extend to an entity that is not expressly listed when blocked persons own, directly or indirectly, 50 percent or more of that entity in the aggregate under OFAC’s 50 Percent Rule. Accordingly, screening only the named customer or employee may be insufficient; organizations may also need to review:
- beneficial ownership
- intermediaries
- account administrators
- actual users
- geographic location, and
- the proposed end use.
A BIS license or license exception does not independently authorize conduct prohibited by OFAC, and an OFAC authorization does not satisfy applicable EAR requirements. Access to software, source code, technical data, cloud platforms, encryption functions, or support services should therefore be evaluated separately under both regimes before credentials are issued or access is activated.
Ordinary systems create overlooked pathways
Email, backups, and automatic replication
Email-related risk extends beyond attachments. Controlled information can appear in the message body, subject line, quoted history, automatic forwarding, distribution lists, or archived mailboxes. In a 2023 ITAR matter involving 3D Systems, the State Department’s proposed charging letter alleged that employee email—including attachments containing technical data—was mirrored automatically to an unencrypted server in Germany. It also described permission changes that removed protections from subfolders and incomplete logging that prevented the company from establishing the full scope of access. Those allegations were resolved administratively and were not adjudicated findings.
Cloud and collaboration platforms
Cloud and collaboration systems add another layer of questions. Where are the primary data, backups, and disaster-recovery copies stored? Who can view plaintext? Can foreign-person administrators, support personnel, contractors, or subprocessors access the material? Do inherited group permissions, public links, previews, indexing, security scanning, or third-party integrations bypass the intended restrictions? A contract promising “U.S. hosting” does not, by itself, answer all of those questions.
Artificial intelligence (AI) tools can create additional pathways if prompts, attachments, generated outputs, telemetry, or retained conversation histories contain controlled material. Before enabling such features, organizations should understand where content is processed and retained, who can access it, whether it is used for model improvement, and whether existing export-control permissions extend to the service and its personnel.
Remote work: location and identity both matter
A virtual private network can secure a connection, but it does not change the worker’s physical location or authorize the recipient. A U.S. person working abroad may still trigger an export-control analysis, while a foreign person working from a U.S. home may still raise a deemed-export issue. For deemed exports, the EAR generally looks to a foreign person’s most recent country of citizenship or permanent residency; the ITAR treats a release as an export to every country in which the person has held or holds citizenship or holds permanent residency.
Identity verification is equally important. In a June 30, 2025 announcement, the U.S. Department of Justice described alleged schemes in which overseas workers used false identities, U.S.-based “laptop farms,” and remote access to appear domestic. DOJ stated that certain workers gained access to sensitive employer information, including export-controlled U.S. military technology. The charged allegations remain subject to the presumption of innocence.
Encryption is conditional protection, not blanket permission
Both the EAR and ITAR contain important exclusions for certain encrypted movements of controlled information, but their conditions are exacting and are not identical.

ITAR § 120.54 provides a similar exclusion for certain unclassified technical data. Among other conditions, the data may not be intentionally sent to a person in, stored in, or sent from a country prescribed under ITAR § 126.1, and the intended recipient must fall within the regulation’s permitted categories. The means of decryption may not be provided to a third party.
Ordinary provider-managed encryption at rest may therefore require closer analysis when a service provider can decrypt, process, inspect, or route plaintext. Encryption also does not authorize an otherwise prohibited person to decrypt the data, and it does not independently authorize a defense service. Whether a particular technical architecture satisfies the EAR or ITAR is fact-specific.
Credentials and software keys require export review
Access controls are not merely a cybersecurity concern. Under EAR § 734.19, transferring access information with knowledge that the transfer will result in an unauthorized release of technology or software requires a comparable authorization. The rule also classifies and controls software license keys under the same Export Control Classification Numbers as the corresponding software or hardware. If a new license requirement later arises because an end user is added to the Entity List, for example subsequent transfers of the software, hardware, and associated keys may require authorization.
Onboarding, restricted-party rescreening, and offboarding should therefore reach beyond the primary user account. Organizations should address:
- active sessions
- multifactor authentication recovery methods
- application tokens
- repository deploy keys
- shared links
- cached copies
- service accounts
- backup access
- remote-management tools
- previously issued software keys.
Build compliance around the access decision
A workable program connects legal classifications to the systems that actually grant access. The following controls form a practical baseline:
Map and classify digital assets. Identify controlled code, drawings, manufacturing data, test results, technical-support material, and defense-service workflows across email, chat, repositories, tickets, endpoints, backups, and collaboration platforms.
Gate access using the relevant facts. Tie permissions to the data’s classification, the user’s verified identity and employer, citizenship or status where applicable, current physical location, screened-party status, authorized end use, and the scope and expiration of any license, agreement, or exception.
Review the architecture – not only vendor labels. Confirm storage and backup regions, administrative-access models, key ownership, subprocessors, logging, plaintext processing, and the handling of previews, search, security scanning, and AI features.
Create change triggers. New hires, contractors, travel, relocation, role changes, acquisitions, integrations, restricted-list updates, and expiring authorizations should trigger renewed access review.
Preserve evidence and test controls. Log viewing, downloading, sharing, privilege changes, and failed access attempts. Test whether distribution groups, parent-folder permissions, alternate file-sharing tools, or remote-access workarounds defeat intended restrictions.
Assign cross-functional ownership. Compliance, legal, human resources, information technology, cybersecurity, procurement, and business teams each hold part of the information needed to make and maintain a defensible access decision.
When potentially unauthorized access occurs
If potentially unauthorized access is detected, the initial response can shape both legal exposure and the quality of the investigation. Businesses should:

Counsel can then help assess jurisdiction and classification, applicable authorizations, destination and end-user restrictions, remediation, recordkeeping, privilege, and whether a voluntary disclosure should be considered. Because early conclusions may change as logs and classifications are reviewed, external communications should be accurate, disciplined, and coordinated.
Frequently asked questions
Can sending controlled information by email count as an export?
Yes. An email can constitute an export when it transmits controlled technology, software, or technical data outside the United States or releases it to a foreign person. The analysis applies to the message body, attachments, quoted history, automatic forwarding, and archived or replicated copies—not only to formal file transfers.
Can access by a foreign-person employee in the United States be an export?
Yes. Under both the EAR and ITAR, releasing certain controlled information to a foreign person in the United States can be a deemed export. The applicable destination analysis differs between the regimes, so citizenship and permanent-residency history must be reviewed under the correct rule.
Does U.S.-based cloud hosting eliminate export-control risk?
No. Domestic hosting addresses only part of the analysis. Organizations must also determine who can access plaintext, where backups and disaster-recovery copies are stored, where administrators and subprocessors are located, and whether previews, indexing, integrations, support tools, or inherited permissions expose controlled material.
Does a VPN or U.S.-issued laptop make overseas access domestic?
No. A VPN can protect a connection, and a company-managed device can strengthen security, but neither changes the user’s physical location nor supplies export authorization. Remote work and international travel should trigger a location-sensitive access review before controlled material becomes available.
Does encryption eliminate the need for an export license?
Not automatically. The EAR and ITAR exclude certain encrypted transmissions or storage only when all regulatory conditions are satisfied. Encryption does not authorize an otherwise prohibited recipient to decrypt the information, and it does not independently authorize a defense service or another controlled activity.
May employees enter controlled information into an AI platform?
Only after an appropriate review. Prompts, attachments, retrieved content, outputs, and retained histories may be processed or accessed by the provider or its subprocessors. The organization should evaluate classification, processing and storage locations, human access, retention, model-training practices, end users, end use, and available authorization.
Can passwords, tokens, or software keys be export-controlled?
Yes, in certain circumstances. EAR § 734.19 regulates certain transfers of access information made with knowledge that they will cause an unauthorized release. Software license keys are generally classified and controlled under the same ECCNs as the corresponding software or hardware.
What should a company do after discovering potentially unauthorized access?
The company should promptly contain access, preserve evidence, and determine what information was available, what was actually accessed or transferred, who was involved, and from which location. Counsel can then assess classification, authorization, remediation, recordkeeping, privilege, and whether a voluntary disclosure should be considered.
Conclusion: Compliance must follow the data
and the user
Digital export risk is created by access, not merely by physical shipment. Effective compliance therefore requires legal classifications to be connected directly to identity management, cloud architecture, cybersecurity, human-resources processes, travel controls, vendor oversight, and incident response.
The central question is no longer simply, “Did we ship anything abroad?” It is: “What controlled information or software could this person access, from where, for what purpose, and under what authorization?” Organizations that can answer that question before access is granted are better positioned to prevent ordinary digital workflows from becoming unauthorized exports.
Key takeaways
- Email, chat, screen sharing, repositories, cloud storage, and remote support can transmit or release export-controlled material.
- User identity, citizenship or status, physical location, end user, end use, and authorization must be evaluated together.
- End-to-end encryption can change the treatment of transmission or storage only when every regulatory condition is met; it does not authorize plain text access.
- Credentials, shared links, tokens, service accounts, and software keys belong in onboarding, rescreening, and offboarding controls.
- Export compliance should be integrated with human resources, information technology, cybersecurity, procurement, travel, and incident response.

ES
RU
TR
FA
AR
ZH