INTERNATIONAL TRADE LAW

Deemed Exports: What US Companies Must Know

A deemed export is the release of controlled technology or source code to a foreign national inside the United States — and it is treated as an export to that person’s home country. No shipment crosses a border. The “export” happens the moment a foreign person can access controlled technical information, whether by reading it, hearing it, or seeing it demonstrated. That makes deemed exports one of the easiest compliance failures to commit without realizing it.

For technology companies, universities, and manufacturers that employ or host foreign nationals, this is not a fringe risk. It is a routine part of hiring, collaboration, and facility tours.

What the regulation actually says

Under the Export Administration Regulations, 15 CFR § 734.13 defines a deemed export as “releasing or otherwise transferring ’technology’ or source code (but not object code) to a foreign person in the United States.” The release is treated as an export to the foreign person’s most recent country of citizenship or permanent residency.

A “release” is broad. Under 15 CFR § 734.15, controlled technology or source code is released through:

  • Visual or other inspection by a foreign person of items that reveal controlled technology or source code; or
  • Oral or written exchange of that technology with a foreign person in the US.

So a deemed export can happen in a hallway conversation, during a lab walkthrough, or by giving an outside contractor access to your internal systems. One important limit: the rule covers technology and source code, not compiled object code, and it does not cover information that is already published or otherwise “publicly available.”

When a license is required

The test mirrors a physical export. If sending the same controlled technology to the foreign national’s home country would require a license, then releasing it to that person inside the US generally requires a license too. To work through it:

  1. Classify the technology. Find its Export Control Classification Number (ECCN) on the Commerce Control List, or confirm it is EAR99. See our guide to classifying goods for export.
  2. Identify the foreign person’s home country of citizenship or permanent residence.
  3. Check the Commerce Country Chart for that ECCN and country to see whether a license is required — the same analysis covered in when you need an export license.
  4. Screen the individual against the BIS Entity List and other restricted-party lists.

Defense technology adds a second regime: technical data on the U.S. Munitions List is controlled by the State Department under ITAR, with its own, stricter licensing rules.

Who is most exposed

Some sectors draw far more scrutiny because their everyday work involves controlled technology and a workforce that includes foreign nationals:

  • Aerospace and defense contracting
  • Semiconductors and advanced electronics
  • Telecommunications and encryption
  • Energy, biotech, and pharmaceutical R&D
  • Universities running federally funded technical research

Research and development carried out at, or shared with, foreign facilities raises the risk further, because controlled technology can change hands long before any product exists.

A cautionary case

The stakes are real. In 2008, Dr. John Reece Roth, a retired University of Tennessee professor, was convicted of violating the Arms Export Control Act for illegally exporting military technical data tied to a US Air Force plasma-technology contract — including by providing controlled defense information to graduate students who were Chinese and Iranian nationals. Roth, then 72, was sentenced to 48 months in federal prison. The case is a defense-side (ITAR) matter rather than an EAR prosecution, but it illustrates the core principle precisely: handing controlled technical data to a foreign national, even on US soil and even without ill intent, can be an unlawful export.

Export violations are generally strict in nature — ignorance or inadvertence is not a defense. That is why proactive controls matter more than good intentions.

How to stay compliant

A workable deemed-export program usually includes: classifying the technology your business handles; screening foreign-national employees, visitors, and contractors; using technology control plans to wall off controlled information; restricting physical and network access; and training staff so they recognize a “release” before it happens. Build the checks into hiring and onboarding rather than bolting them on after a problem surfaces.

FAQ

What is a deemed export in plain terms? It is giving a foreign national in the US access to controlled technology or source code. The law treats that access as if you had shipped the technology to that person’s home country.

Does the deemed export rule apply to all foreign employees? It applies when the technology is controlled for the employee’s home country. If the item is EAR99 or the technology is publicly available, a license is typically not required — but you should run the analysis rather than assume.

Is software covered? Source code can be a deemed export; object (compiled) code is not covered by the deemed export rule. Other EAR controls may still apply to software.

What are the penalties for a deemed export violation? They can be severe — substantial civil penalties and, in serious cases, criminal prosecution. Violations generally do not require intent, so unintentional releases can still be unlawful.

Hiring foreign nationals or sharing technical data? Reidel Law Firm prepares flat-fee Import/Export Compliance Memos and technology control plans that map your deemed-export exposure and the licenses you may need — with direct attorney access. Request a compliance memo →

← All articles