| Key Takeaways
• AI use does not automatically fall outside ITAR just because current ITAR regulations do not explicitly mention artificial intelligence. • Several important AI-specific questions, such as whether trained models or AI-generated outputs retain ITAR control status, remain unresolved and is awaiting DDTC guidance. • However, putting ITAR-controlled technical data into an AI system can constitute a disclosure or export, depending on who can access the data and how the AI system handles it. • Organizations can reduce compliance risk by protecting technical data itself with persistent access controls, traceability, and governed AI environments. |
Across organizations, engineering teams have adopted AI assistants faster than compliance programs have adapted. CAD files are being edited, specifications drafted, and source code reviewed at this very moment with AI tools. In most cases no policy was broken, because no policy existed.
This raises a question many compliance programs have not yet asked: when an engineer places export-controlled technical data into an AI system, what has occurred under the International Traffic in Arms Regulations (ITAR)?
No ITAR provision currently mentions artificial intelligence. However, the definitions governing technical data, export, and release were written to be neutral as to technology.[1][2][3] Therefore, no AI rule does not mean an AI exemption.
Why the Absence of an AI Rule is not an Exemption
ITAR defines technical data by what the information does, not by the form it takes or the tool that handles it. The definition covers information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, including blueprints, drawings, plans, instructions, and documentation.[1] Nothing in that definition depends on how the information was produced or where it was placed.
The same is true of disclosure. An export occurs when technical data is sent or taken out of the United States, and also when it is released to a foreign person within the United States, a situation commonly described as a “deemed export”.[2] “Release” includes visual inspection and oral or written exchange of technical data.[3]
Independent legal analysis published in December 2025 reaches the same conclusion, noting that the definition of technical data turns on functional characteristics, regardless of whether the information was produced by a human engineer, copied from a blueprint, or generated by a model. So, while the DDTC has not yet issued authoritative guidance on the question, ITAR definitions do not exclude AI models from scrutiny.[4]
What is Settled and What is Awaiting Guidance
Distinguishing between the two protects an organization from complacency.
Well-supported under existing regulation:
- A foreign person who obtains controlled technical data from an internal or private AI model, unaltered by the model, has received a disclosure.[2][3]
- Placing controlled technical data into a public AI service makes that data readable by a third party. The ITAR encryption provision, which allows unclassified technical data to be sent and stored without a license, requires that the means of decryption not be provided to an unauthorized foreign person.[5]
- Records of exports, disclosures, and authorizations must be retained for five years and must be capable of showing who accessed what, and under what authority.[6]
Awaiting guidance:
- Whether a model trained on controlled data is itself a repository of technical data.
- Whether output generated from controlled input carries the same control status. Commentary notes that the public domain exclusion does not apply automatically, because a model may synthesize information that never existed in published form, and because a response generated for one user is not publication to the public.[4]
- Who is treated as the exporter when a model, rather than a person, produces the controlled information.[4]
Organizations waiting for these questions to be resolved should note that none of them affect the list of items that are already settled under current ITAR regulations.
An ITAR Compliant Approach to AI Usage
Controls that sit at the perimeter, or at the repository, do not travel with the file into an AI workflow. Controls attached to the data itself do.[7]
- Persistent protection of technical data. Files are protected at creation and download, so that safeguards remain effective regardless of which AI model the file is later placed into.
- Eligibility-based access control. Permission to render a file in readable form is tied to identity, role, project context, and export authorization status, whether the request comes through a desktop application or an AI environment.
- End-to-end traceability. File activity is logged at the level of the individual, including access, modification, printing, and screen capture, producing the record that recordkeeping obligations assume exists.
- Governed AI environments. Where AI is necessary for the work, it operates on approved data within a controlled environment, so that productivity does not depend on moving controlled files outside the organization’s authority.
Conclusion
Export compliance has always adapted to new technology. Each time, organizations assumed a new tool sat outside them until told otherwise. AI is at that stage now.
Despite the absence of explicit AI-related rules, the obligations in ITAR that already exist can reach AI usage. They carry the consequences they have always carried. Organizations that embed protection, eligibility, and visibility into the technical data itself are positioned to adopt AI without waiting for guidance.[4][7]
Sources & References
[1] 22 CFR § 120.33, Technical data. eCFR, current text: gov
[2] 22 CFR § 120.50, Export. eCFR, current text: gov
[3] 22 CFR § 120.56, Release. eCFR, current text: gov
[4] Joe Khawam and Tim Schnabel, “AI Model Outputs Demand the Attention of Export Control Agencies,” Just Security (Reiss Center on Law and Security, NYU School of Law), December 12, 2025: org
[5] 22 CFR § 120.54, Activities that are not exports, reexports, retransfers, or temporary imports. eCFR, current text: gov
[6] 22 CFR § 122.5, Maintenance of records by registrants. eCFR, current text: gov
[7] Fasoo White Paper, When Borders Matter: Securing Export-Controlled Technical Data under ITAR (Fasoo, 2026)
This article is general information about export control regulations, not legal advice. As of September 2026, the authors are not aware of any ITAR provision or DDTC guidance addressing artificial intelligence specifically; readers should verify the current position against the eCFR and DDTC publications and consult qualified export control counsel before relying on any analysis here for a specific workflow. Regulatory text cited was checked against the eCFR edition current as of September 2026.