What Are Export Controls and Why Startups Must Care

Export controls are licensing-and-screening rules for dual-use and defense technology, where compliance depends on item classification plus destination, end user, end use, and intangible transfer, not just whether a product is on a list. In the United Kingdom's 2024 data, 11,415 standard individual export licence decisions produced 10,815 approvals and 600 refusals, showing that licensing is an active business process, not a theoretical rule.

A Seattle startup can discover that during an ordinary product launch. An engineer shares model documentation with a contractor abroad, a cloud administrator grants access to a foreign affiliate, or a sales team accepts an order from a new market. No crate crosses a dock, yet the company may have transferred controlled software, technical data, or know-how. Founders who ask “what are export controls?” need more than a dictionary definition. They need a practical system for classifying technology, screening relationships, monitoring rule changes, and documenting decisions.

What Export Controls Really Mean for Modern Businesses

A software company may treat a shared repository as an internal workspace. A regulator may view the same repository as a channel through which controlled technology becomes available outside the company's permitted environment. That difference matters when the repository contains source code, encryption functionality, advanced computing information, technical instructions, or data connected to a controlled product.

Export controls work like airport security for sensitive innovation. Airport security doesn't inspect only the traveler's suitcase. It also considers the traveler, the destination, the route, and the circumstances. Export compliance follows a similar logic. A company evaluates the item, the destination, the recipient, the intended use, and the method of transfer before deciding whether authorization is required.

The system exists because governments use trade rules to address national security, nonproliferation, defense, foreign-policy, and human-rights concerns. Major economies have used export controls as a policy tool more frequently since 2018, according to Global Trade Alert's analysis of the temporal dimensions of export controls. The same analysis identifies 591 active export controls and 606 concluded measures, with China accounting for 318 interventions, nearly two-thirds of which were classified as harmful. U.S. measures also lasted longer at the median than EU27 measures, which makes monitoring part of ordinary operations for internationally active businesses.

An infographic titled What Export Controls Really Mean for Modern Businesses, highlighting four key aspects of compliance.

Why early-stage companies fall within the perimeter

Export controls aren't limited to weapons manufacturers. A young company may handle:

  • Cloud-hosted software: Access from another country can create a controlled transfer question.
  • Technical data: Architecture diagrams, training instructions, and engineering notes may matter as much as hardware.
  • Artificial intelligence tools: Model weights, advanced computing capabilities, and supporting technology can attract heightened scrutiny.
  • Commercial components: A product made for civilian customers may still have military applications.

The United Kingdom's system illustrates how established this process is. The government has published annual reports on export licensing decisions since 1997, added quarterly reports from 2004, and included trade control licence data from 2005. Country-level licensing data has been available through the official statistics portal from January 2008 onward, according to the UK export control database.

The practical definition is therefore broader than “permission to ship a restricted product.” Export controls are a gatekeeping system for technology, software, data, services, and relationships. The startup that builds a repeatable review process early can make expansion decisions with fewer surprises.

How Dual Use Technology and Intangible Transfers Trigger Controls

Dual-use technology has a civilian purpose and a potential military, security, or strategic purpose. A sensor may support industrial automation and also assist military navigation. Encryption software may protect ordinary business communications and also support sensitive government systems. The technology doesn't become controlled merely because someone labels it “high tech.” Classification and context determine the analysis.

The European Union framework captures the breadth of the system. It covers goods, software, and technology, and can also reach brokering, technical assistance, transit, and transfers of listed items. Catch-all rules can extend controls to unlisted items when a business knows or suspects a connection to weapons of mass destruction, military end use, or certain human-rights concerns, as described in the European Parliament briefing on dual-use export controls.

Practical rule: A product-list check is only the first question. Destination, end user, end use, and transfer method can change the answer.

The intangible transfer problem

A physical shipment is easy to visualize. An intangible transfer is easier to miss. A company may export technology when it:

  1. Emails controlled technical data to an overseas recipient.
  2. Gives a foreign national access to restricted source code.
  3. Uploads controlled files to a cloud environment that permits access from another jurisdiction.
  4. Provides technical training or troubleshooting to an overseas customer.
  5. Shares model weights, design specifications, or production know-how through a collaboration platform.

This doesn't mean every email or cloud login requires a licence. It means the company must identify what was transferred, who could access it, where access occurred, and whether the relevant rules require authorization. A separate review of cross-border data transfer mechanisms can help identify privacy and contractual issues that may sit alongside export-control analysis.

A startup developing an industrial AI platform offers a useful example. Its software may be sold for factory maintenance, but the engineering team also provides deployment guidance to a foreign affiliate. The company should review the software's classification, the affiliate's location, the personnel who receive the guidance, and the customer's stated use. If the facts raise a catch-all concern, the absence of a product-list match won't end the inquiry.

The same logic applies to intermediaries. A business arranging a transfer between two other parties may face brokering obligations even if it never owns the item. A consultant delivering know-how abroad may create a technical-assistance issue without shipping anything. Export control analysis follows the substance of the transfer, not merely the title on a purchase order.

Major U.S. Regimes and Global Frameworks You Should Know

Founders usually need a map before they need a statute book. In the United States, the central divide is between the Export Administration Regulations, commonly called the EAR, and the International Traffic in Arms Regulations, commonly called ITAR.

The EAR generally covers commercial and dual-use items. Items not listed on the Commerce Control List are generally treated as EAR99, although an EAR99 item may still require a licence when the destination, recipient, or intended use creates a restriction. ITAR governs defense articles and defense services connected to the U.S. Munitions List and is typically more restrictive. The practical distinction is summarized in this explanation of commercial and dual-use items under the EAR.

Regime Scope and Items When It Applies
EAR Commercial items, dual-use goods, software, and technology, including listed items and many EAR99 items When the item is subject to the EAR and the destination, end user, end use, or other rule creates a licensing requirement
ITAR Defense articles, defense services, and technical data connected to the U.S. Munitions List When a product or service falls within the defense-specific system
Multilateral controls Shared principles that influence national dual-use lists and controls on sensitive conventional arms and technology When a national authority incorporates the relevant policy into its own regulations and lists

Why jurisdiction can follow the product

The EAR’s scope reaches beyond a shipment leaving a U.S. warehouse. Under EAR Part 734, the United States applies a 25% de minimis threshold to certain foreign-made commodities that incorporate controlled U.S.-origin commodities or are bundled with U.S.-origin software. Some foreign-made products therefore become subject to U.S. controls when the controlled U.S. content exceeds 25% of total value.

That rule can matter to a company that manufactures abroad, works through a contract manufacturer, or sells a product assembled outside the United States. The relevant question isn’t where final assembly occurs. The company must examine U.S.-origin inputs, software, destination rules, and the specific de minimis provision.

The Wassenaar Arrangement also matters as a global reference point. It supports many national dual-use control lists and aims to prevent destabilizing accumulations of sensitive conventional arms and dual-use technologies. It doesn’t replace national law. A Washington startup still needs to identify the controlling U.S. regime, then account for the rules of other jurisdictions involved in manufacturing, development, cloud hosting, sales, or support.

How Classification Screening and Licensing Actually Work

A founder evaluating a new foreign customer shouldn’t begin with “Can the sales team ship this?” The better starting point is a documented sequence that separates classification from screening. Each step answers a different question, and skipping one can produce a false sense of safety.

The five-part review

  1. Classify the product. Engineering and compliance personnel identify the relevant control-list category, technical specifications, software functionality, and applicable jurisdiction. Under the EAR, that may involve determining an Export Control Classification Number, or ECCN, rather than stopping at the broad label “software.”

  2. Check the lists. The company compares the item against the relevant national and regional control lists. An item can be unlisted under one regime and controlled under another, so product records should identify jurisdictional assumptions instead of relying on a single global label.

A five-step flowchart explaining the export classification screening and licensing process for international trade compliance.
  1. Screen the destination. Sanctions, embargoes, country-based controls, and destination-specific licensing policies can change the outcome. A seemingly ordinary product may require authorization for one destination but not another.

  2. Screen the recipient and use. The company checks the customer, beneficial relationships, affiliates, intermediaries, and stated end use. Sales pressure shouldn’t override an unresolved red flag, especially where the customer gives vague answers about installation, ownership, or final use.

  3. Make the authorization decision. The business determines whether a license is required, whether an exception or exemption is available, and what records support the decision. If the answer remains uncertain, the company pauses the transaction and escalates the review.

A vendor assessment can make the fourth step more reliable, especially when a startup shares software or technical data with contractors. A structured vendor risk assessment should record location, access rights, subcontractors, ownership, purpose, and controls around onward transfer.

Why reexports deserve attention

A product assembled outside the United States may still carry U.S. export-control consequences. The EAR’s 25% de minimis threshold applies to certain foreign-made commodities containing controlled U.S.-origin commodities or bundled with U.S.-origin software, and some reexports become subject to U.S. controls when U.S. content exceeds that threshold, as explained by the Bureau of Industry and Security’s EAR Part 734 provisions.

The same product may also encounter scheduled list changes. The EU updated its dual-use control list in September 2026. The update becomes effective only after publication in the Official Journal and a two-month scrutiny period by the Council and European Parliament, according to the European Commission’s update notice. Canada’s control guide likewise operated under a dated version that remained effective until April 30, 2026, as shown in Canada’s export-control backgrounder.

Penalties Enforcement and Why Compliance Risk Is Rising

Export-control exposure has several layers. A company may face civil enforcement, criminal liability for willful conduct, denial of export privileges, shipment delays, contract problems, investor concern, and reputational damage. The exact consequence depends on the applicable regime, the conduct, the company’s knowledge, and the enforcement authority, so a generic penalty figure would mislead more than it would help.

The operational risk grows when a company treats compliance as a one-time legal memo. A classification completed during product launch can become stale after an engineering change, a new cloud architecture, a new customer, or a regulatory amendment. A founder who delegates the issue to sales without maintaining the underlying decision record may not know why an earlier transaction was permitted.

The rulebook keeps moving

The United Kingdom’s 2025 annual report provides a concrete signal. The Export Control Joint Unit issued 34 Notices to Exporters during the year, while compliance checks increased to 383 in 2025 from 270 in 2024, according to the UK Strategic Export Controls Annual Report 2025. Those figures don’t prove that every company faces the same level of scrutiny, but they do show why a static policy can fail in a changing environment.

Global Trade Alert’s research also describes export controls as an increasingly used policy instrument across China, the United States, and the EU27 since 2018. China’s controls included 318 interventions, and the analysis distinguishes measures by duration and whether they were harmful. For a startup with customers, suppliers, or investors across several markets, regulatory change is a business continuity issue as much as a legal issue.

A practical monitoring process should assign an owner, record the date of each review, and connect changes to affected products and transactions. Teams looking to formalize that process can use this continuous compliance monitoring guide as a planning resource.

Operational warning: A company can make a reasonable decision under an old rule and still create risk by continuing to apply it after the rule changes.

Practical Compliance Steps for Startups and Tech Companies

A startup doesn’t need a large department to begin. It does need ownership, repeatable questions, and records that explain why a transaction moved forward. A lightweight program can sit inside product operations, procurement, sales approval, and information-security workflows.

Build the operating layer

  • Create a technology register: List hardware, software, source code, technical data, model weights, documentation, and services. Record the jurisdictions connected to development, hosting, support, and delivery.
  • Assign classification responsibility: Product and engineering teams should supply technical facts. Legal or compliance personnel should assess the applicable rules and preserve the reasoning.
  • Control access deliberately: Use role-based permissions for sensitive repositories and cloud environments. A user’s employment title isn’t enough to establish that access is permitted.
  • Screen before commitment: Add destination, customer, affiliate, intermediary, and intended-use questions to sales, procurement, and partnership intake.
  • Maintain an update log: Record regulatory notices, list changes, affected products, policy owners, and the date when the company completed its impact review.
  • Preserve evidence: Keep classification notes, screening results, license decisions, exception analysis, customer representations, and escalation records together.

The question many explainers miss is whether controls apply when the company isn’t the exporter of record. The answer may still be yes, depending on the transfer, the technology, the parties, the jurisdiction, and the applicable rule. Cloud access, technical support, affiliate collaboration, and a subcontractor’s use of controlled inputs can all require careful analysis without a conventional shipment.

Watch supply-chain and affiliate exposure

Recent developments make that point concrete. China’s October 2025 measures broadened controls to products, technologies, and services tied to rare-earth materials and extended some provisions extraterritorially to items made outside China using controlled Chinese inputs, as discussed in AlixPartners’ review of foreign sanctions and export-control developments. The implication for a technology company is straightforward: procurement and manufacturing records may belong in export analysis, not just shipping records.

A company expanding from Washington can also consult the AUSFF export guide for practical shipping and export-process context, while recognizing that U.S. and transaction-specific legal questions require their own analysis. For a broader governance structure, a compliance-program legal guide for Seattle corporations can help connect export review to contracts, privacy, cybersecurity, and vendor management.

When to Seek Legal Counsel and Next Steps for Growth

Self-management can work for a company with a narrow product range, straightforward domestic operations, transparent customers, and no obvious controlled technology. Legal counsel becomes more valuable when the company enters a new market, develops advanced computing or AI capabilities, works with defense customers, uses complex supply chains, or gives overseas personnel access to technical data.

Counsel should also be involved when a transaction presents uncertainty rather than a clear answer. Warning signs include a customer that refuses to identify the end user, a distributor that changes the stated destination, an affiliate that wants broad repository access, a contract manufacturer using controlled inputs, or an engineering team that wants to transfer source code through an overseas cloud environment.

Prepare before the consultation

A founder can make the review faster by assembling:

  • A product and technology inventory.
  • Technical specifications and proposed classifications.
  • Customer, distributor, affiliate, supplier, and manufacturing locations.
  • Intended end uses and known end users.
  • Cloud-hosting and access arrangements.
  • Prior licenses, screening records, and internal policies.
  • A list of transactions that are urgent, unusual, or unresolved.

A business lawyer can also place export questions in their commercial setting, including contracts, intellectual property ownership, trade-secret controls, privacy obligations, and corporate approvals. A general guide for corporate legal teams may help executives define the internal roles that support that work. Companies evaluating broader legal needs can review what a business lawyer does before deciding which issues require specialized advice.

The most useful decision is rarely “Can the company avoid all export controls?” A better question is whether the company can identify controlled technology, screen the right people and destinations, track changes, and stop when the facts don’t fit the existing policy. Early review gives founders a clearer path to growth and reduces the chance that an informal software share becomes a regulatory problem.


By Design Law Firm & Legal Consultancy, PLLC helps startups and technology companies assess export-control questions alongside contracts, data transfers, cybersecurity, trade secrets, and broader compliance programs. Visit By Design Law Firm & Legal Consultancy, PLLC to discuss a practical review of the company’s technology, counterparties, and international growth plans. Call our law office at (206) 593-1519.

Our Blog​

Related News and Articles