TIMEWELL
Solutions
Free ConsultationContact Us
TIMEWELL

Unleashing organizational potential with AI

ISO/IEC 27001 (ISMS) certification mark (SGS / ISMS-AC)

ISO/IEC 27001:2022 certified Certificate No. JP26/00000255 Scope: Planning, development and operation of SaaS products utilizing AI technology

Services

  • ZEROCK
  • TRAFEED (formerly ZEROCK ExCHECK)
  • TIMEWELL BASE
  • WARP
  • └ WARP 1Day
  • └ WARP NEXT Corporate
  • └ WARP BASIC
  • └ WARP ENTRE
  • └ Alumni Salon
  • └ WARP for Schools
  • AI Consulting
  • ZEROCK Buddy

Company

  • About Us
  • Team
  • Why TIMEWELL
  • News
  • Contact
  • Free Consultation

Content

  • Insights
  • Knowledge Base
  • Case Studies
  • Whitepapers
  • Events
  • Solutions
  • AI Readiness Check
  • ROI Calculator

Legal

  • Privacy Policy
  • Manual Creator Extension
  • WARP Terms of Service
  • WARP NEXT School Rules
  • Legal Notice
  • Security
  • Anti-Social Policy
  • ZEROCK Terms of Service
  • TIMEWELL BASE Terms of Service

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

© 2026 株式会社TIMEWELL All rights reserved.

Contact Us
HomeColumnsTRAFEEDComplete Guide: Where the EU AI Act Meets Export Control — The 2 August 2026 General Application Date and the Dual-Use Regulation Intersection
TRAFEED

Complete Guide: Where the EU AI Act Meets Export Control — The 2 August 2026 General Application Date and the Dual-Use Regulation Intersection

Published2026-05-20Updated2026-08-02Ryuta Hamamoto
EU AI Actexport controlGPAIDual-Use RegulationAnnex IIIsystemic riskTRAFEED

A beginner-friendly guide to where the EU AI Act (Regulation 2024/1689) meets the EU Dual-Use Regulation (Regulation 2021/821).

Complete Guide: Where the EU AI Act Meets Export Control — The 2 August 2026 General Application Date and the Dual-Use Regulation Intersection
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. The EU AI Act (Regulation (EU) 2024/1689) has expanded application step by step since its August 2024 entry into force, and the general application date set by Article 113 — 2 August 2026 — has now arrived.

Let me clear up the most common misreading first. High-risk AI did not come into full application on that date. What started is Chapter IV (Article 50 transparency duties), Chapter III Section 5 (Articles 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapters VI and VIII–XI, and the Commission's power to fine GPAI providers (Article 101). The substantive high-risk obligations were rescheduled by the amending act Regulation (EU) 2026/1744 (adopted 8 July 2026; published as OJ L 2026/1744 on 24 July 2026; in force 27 July 2026), which moved Chapter III Sections 1, 2 and 3 (excluding Article 6(5)) to 2 December 2027 for Annex III type (Article 6(2)) and 2 August 2028 for Annex I type (Article 6(1), embedded in products). Only those three sections moved; Section 5 of the same chapter has been running since 2 August.

I keep hearing the same stuck question from owners: is the EU AI Act a product-safety regime or an export-control regime? Short answer: product safety. But the eight high-risk AI fields in Annex III largely overlap in practice with "cyber-surveillance items" as understood in export control. When high-risk AI is re-exported from the EU (especially to destinations that raise Dual-Use Article 5 end-use concerns), a separate export license under EU Dual-Use Regulation 2021/821 may also be required.

Japanese AI companies need to watch both conformity assessment for placing AI products on the EU internal market (AI Act) and export licensing for shipments from the EU to third countries (Dual-Use Reg). U.S. ECCN 4E091 / GP10 and Japan's Foreign Exchange and Foreign Trade Act catch-all revisions are moving in parallel. That is a four-layer stack.

Below I map the intersections so export-control practitioners can decide what to organize, and by when.

What you will learn

  • The AI Act’s four risk tiers and what does — and does not — start on 2 August 2026
  • The high-risk AI dates (Annex III type: 2 December 2027; Annex I type: 2 August 2028) and where Regulation (EU) 2026/1744 fits
  • How Annex III high-risk AI fields overlap with Dual-Use Regulation “cyber-surveillance items”
  • GPAI Model systemic-risk duties and the 10^25 FLOPs threshold
  • How U.S. ECCN 4E091 / GP10 guidance maps to the EU (with comparison table)
  • Three typical scenarios for Japanese companies and five practical steps

Three terms to understand first

Without shared vocabulary, AI Act × export-control discussions go off track quickly.

EU AI Act — product-safety regulation for AI systems

Formally Regulation (EU) 2024/1689. Entered into force August 1, 2024; applies by risk tier on a phased schedule. It is a product-safety regulation.

The key point: the AI Act regulates parties that place AI systems on the EU internal market. "Placing on the market" means first making available for sale or use in the EU. The AI Act does not itself stop exports. High-risk systems, however, substantially overlap export-control cyber-surveillance concepts, so they also catch on the export-control lane.

GPAI (General-Purpose AI Model)

Models trained with more than 10^23 FLOPs that can generate text, audio, image, video, and similar modalities. GPT, Claude, Gemini, Llama, Mistral, and peers almost certainly fall in this bucket.

GPAI duties applied from 2 August 2025 (copyright summary of training data, technical documentation, etc.). Models above 10^25 FLOPs carry heavier systemic-risk GPAI duties.

Systemic risk — the "heavy" compute-based tier

Under Article 51(2), GPAI models whose training compute exceeds 10^25 FLOPs are presumed to present systemic risk. Providers must notify the European Commission within two weeks of crossing the threshold; red-teaming, serious-incident reporting (within 72 hours), and cybersecurity of model weights are required.

The Commission does not publish a definitive count of in-scope models, so this article does not cite one. The point that matters: companies training large LLMs in-house cannot treat this threshold as someone else's problem.

Four risk tiers and fines

Risk tier Examples Application date Main duties
Unacceptable Risk (prohibited) Social scoring; emotion inference in the workplace (Article 5(1)(f)); real-time remote biometric ID in public spaces 2 February 2025 (Article 5) Full ban
High Risk Annex III eight fields (Article 6(2)) 2 December 2027 Conformity assessment / technical docs / risk management / human oversight / deployer duties and FRIA
High Risk Annex I product safety components (Article 6(1)) 2 August 2028 Same
Limited Risk Chatbots; deepfakes; generative AI outputs 2 August 2026 (Article 50) Transparency (disclose AI-generated content; machine-readable marking)
Minimal Risk Spam filters; recommenders Out of scope Optional codes of conduct

Phased application schedule (Article 113, as amended by 2026/1744)

The general application date itself did not move: the second paragraph of Article 113 ("It shall apply from 2 August 2026") was left unamended. What changed are the staged exceptions around it.

Date What starts applying
2 February 2025 Chapter I (scope, definitions, Article 4 AI literacy) and Chapter II (Article 5 prohibited practices)
2 August 2025 Chapter III Section 4 (notifying authorities), Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties, Articles 99 and 100 — but not Article 101), Article 78
27 July 2026 Regulation (EU) 2026/1744 enters into force; AI Act Articles 102–110 (amendments to other instruments) start applying
2 August 2026 (general application date) Chapter IV (Article 50 transparency duties), Chapter III Section 5 (Articles 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapter VI, Chapters VIII–XI, and Article 101 (Commission's power to fine GPAI providers)
2 December 2026 New prohibitions: Article 5(1)(ba) (non-consensual sexual deepfakes), 5(1)(bb) (CSAM generation), and Article 5(1a)(1b). Also the new Article 111(4) deadline: providers of synthetic-content generating AI placed on the market before 2 August 2026 must comply with Article 50(2) by this date
2 August 2027 Article 111(3): compliance deadline for GPAI models placed on the market before 2 August 2025
2 December 2027 Annex III high-risk AI (Article 6(2)) becomes subject to Chapter III Sections 1, 2 and 3. Article 22 (authorised representative), Article 25 (value chain), Article 26 (deployer duties) and Article 27 (FRIA) also start here
2 August 2028 Annex I high-risk AI (Article 6(1), embedded in products) becomes subject to the same Sections
2 August 2030 / 31 December 2030 Article 111(2) (use by public authorities) / Article 111(1) (Annex X large-scale IT systems)

Two misreadings worth killing off:

  1. "High-risk AI applies in full on 2 August 2026" is wrong. The substantive high-risk obligations start on 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type). What starts on 2 August 2026 is Article 50 transparency and the Commission's Article 101 GPAI fining power, among others.
  2. "Article 50 transparency was pulled forward to 2 December 2026 / the grace period was shortened" is also wrong. Chapter IV appears in none of the exceptions in the third paragraph of Article 113, so Article 50 still applies from 2 August 2026. Regulation 2026/1744 amended only Article 50(7) (codes of practice); the substantive duties in paragraphs (1)–(6) are unchanged. What happens on 2 December 2026 is the start of the new prohibitions and the Article 111(4) transitional deadline for existing systems.

Fines up to 7% of worldwide annual turnover

Article 99 sets ceilings heavier than GDPR in key cases:

  • Prohibited AI: up to €35 million or 7% of worldwide annual turnover (whichever is higher)
  • Other duty breaches: up to €15 million or 3%
  • False information: up to €7.5 million or 1%

"7%" exceeds GDPR's 4%. For Japanese companies with EU revenue, this is not a soft obligation.

Annex III high-risk AI and the export-control intersection

This is the core of the article. The eight high-risk fields in Annex III to the AI Act conceptually overlap EU Dual-Use Regulation 2021/821 cyber-surveillance items.

Rough map:

  • EU AI Act: conformity assessment and CE marking for high-risk AI sold or used inside the EU
  • EU Dual-Use Reg: export licenses for cyber-surveillance-related items exported from the EU to third countries

The same AI system can hit the AI Act inside the EU and Dual-Use Reg on the way out. Highest-overlap fields:

Annex III field Export-control overlap Related Dual-Use entries / articles
1. Biometrics (ID, classification, emotion inference) Face / iris / voice cyber-surveillance items Annex I 5A001.f / 5D001; Article 5 catch-all
2. Critical infrastructure (power, water, transport, digital) SCADA / ICS control software Annex I 4D / 5D cyber-related
3. Education and vocational training Limited —
4. Employment and worker management Limited —
5. Essential services (credit, insurance, social benefits) Limited —
6. Law enforcement (predictive policing, polygraphs, etc.) Human-rights-sensitive cyber-surveillance Article 5 catch-all
7. Migration and border management Same Article 5 catch-all
8. Administration of justice and democratic processes Limited —

One practical takeaway: if you handle AI in biometrics, critical infrastructure, law enforcement, or migration/border management, watch both high-risk AI Act duties and Dual-Use Article 5 catch-all.

Article 5: cyber-surveillance catch-all

Article 5 of Dual-Use Regulation 2021/821 requires an export license for non-listed items when the exporter knows, or has reasonable grounds to suspect, use for human-rights abuses, internal repression, or serious IHL violations. AI alone is rarely listed, but systems combining AI with other cyber-surveillance technology can fall under catch-all.

On October 15, 2024 the Commission published due-diligence guidelines that effectively raise exporter investigation expectations.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Download Product CatalogContact About TRAFEED

GPAI duties and systemic risk (10^25 FLOPs)

Especially relevant for companies training large LLMs in-house.

Common GPAI duties (from 2 August 2025)

  • Publish a copyright summary of training data
  • Maintain technical documentation (architecture, training data, capability evaluations)
  • Information duties toward downstream providers
  • Cooperation with the EU AI Office

Additional systemic-risk GPAI duties

Models above 10^25 FLOPs are presumed systemic-risk and must also:

  1. Model evaluation: adversarial testing / red-teaming under standardized protocols
  2. Systemic-risk assessment and mitigation
  3. Serious-incident reporting to the AI Office within 72 hours
  4. Cybersecurity: protect model weights against exfiltration
  5. Energy-consumption disclosure
  6. Maintain and update a Safety and Security Framework

Model-weight protection is the closest link to export control. U.S. ECCN 4E091 regulates "AI model weights" as such. EU GPAI duties and U.S. EAR point in the same direction.

Timeline

Date Content
2 August 2025 GPAI duties (Chapter V) begin. Penalties under Articles 99 and 100 also start (Article 101 excluded)
2 August 2026 Article 101 starts applying: the Commission gains the power to fine GPAI providers
2 August 2027 Article 111(3): compliance deadline for GPAI models placed on the market before 2 August 2025

To be precise: the 2 August 2026 milestone here is about Commission supervision and enforcement over GPAI providers. It is a separate lane from the substantive high-risk obligations. Coverage that summarises this as "full application in August 2026" will mislead you if you read high-risk AI into it.

Dual-Use Regulation 2021/821 and AI-related entries

EU Dual-Use Annex I Content
5A001.f Communications interception / cyber-surveillance equipment
5D001 Software for the above
4A005 / 4D004 Intrusion software
3A001.z / 4A090 Advanced computing ICs (AI-training GPUs, etc.; 2025 update considerations)
500 series (adopted September 8, 2025) EU-autonomous emerging-tech entries (semiconductor equipment, quantum, etc.)

Delegated Regulation 2025/2003 (adopted September 8, 2025) fully replaces Annex I and creates the EU-autonomous "500 series" for semiconductor equipment, quantum computing, cryogenics, and more. Some AI-training GPUs are regulated indirectly through this structure.

Details: Complete guide to the EU Dual-Use Regulation 2025 amendment (2025/2003). Read it together with AI Act planning.

Comparison with U.S. ECCN 4E091 / GP10

ECCN 4E091: model weights regulated directly

Created under the January 2025 AI Diffusion Rule, ECCN 4E091 treats model weights of advanced closed-weight AI models as controlled items. Among the first laws worldwide to treat AI models as physical export items.

The Trump administration later signaled withdrawal of the AI Diffusion Rule and is developing a successor. The "model weights equal controlled items" framing is still expected to persist as a baseline for other jurisdictions (see AI Diffusion Rule withdrawal and alternatives).

GP10: end-use / end-user catch-all

General Prohibition 10 under the EAR bars unlicensed exports when the exporter knows, or has reason to know, that end use or end user presents covered concerns. Japan is a lower-risk destination in principle, but third-country routing still requires care.

EU vs. U.S.

Item EU U.S.
Direct model-weight control No (indirect via GPAI duties) Yes (ECCN 4E091)
Extraterritorial reach Applies when outputs are used in the EU EAR applies to re-exports of U.S. software
End-use diligence Article 5 catch-all GP10 across items
Penalties Up to €35M / 7% worldwide turnover Up to $1M per count + criminal
Regulatory philosophy Product safety + human rights National security

EU is product safety and human rights; U.S. is national security. Understanding both "whys" reduces friction in internal reviews.

Three impacts on Japanese companies

Impact 1: Selling Japanese AI products into the EU

Example: a Japanese AI vendor supplies credit-scoring AI to a European bank. Credit scoring falls under Annex III “essential services” → high-risk AI.

Required action Application date
Appoint an EU authorised representative (Article 22) 2 December 2027
Conformity assessment (technical docs, risk management, testing vs. high-risk requirements; third-party or self-assessment) Same (the framework itself — Chapter III Section 5, Articles 40–49 — applies from 2 August 2026)
CE marking and EU database registration Same (again, the Articles 40–49 framework applies from 2 August 2026)
Technical documentation and risk-management system 2 December 2027
Human oversight and cybersecurity measures Same
Deployer duties (Article 26) and fundamental rights impact assessment / FRIA (Article 27) Same
Transparency duties for generative AI output (Article 50) 2 August 2026

For Annex I type systems (embedded in products, Article 6(1)), the Chapter III Sections 1–3 date is 2 August 2028 instead.

Expect 6–12 months of preparation. With the Annex III date at 2 December 2027, build the internal schedule by working backwards from it.

Impact 2: Parallel response to Japan's catch-all reform

Japan's FEFTA catch-all reform of October 9, 2025 designated semiconductors and machine tools as "core items." On February 14, 2026 a bulk-license regime for defense-equipment maintenance parts was also introduced.

Example path: buy AI-training GPUs in the EU and ship to a Chinese customer via Singapore.

  • EU: Dual-Use Annex I semiconductor entries, then EU export license
  • U.S.: if U.S.-origin, EAR re-export (even EAR99 can engage GP10)
  • Japan: FEFTA catch-all; Singapore routing can still be treated as China-bound if that is the substance

Three-layer checks run at once. The AI Act connects indirectly because GPAI weight-protection duties govern when and to whom weights are released (see How EAR, China, and EU export controls hit at once).

Impact 3: Ambiguous military-exclusion boundary under Article 2

AI Act Article 2(3) excludes AI for military, defense, and national-security purposes. In practice the boundary is fuzzy.

  • Military-developed AI later used for civilian purposes: AI Act applies
  • Civilian-market AI later used for military purposes: AI Act does not apply under Article 2(3)
  • Dual-use items (civilian and military) are effectively under AI Act regulation when placed on the market

"Military-only, so irrelevant" is a risky call. Most AI systems are positioned as civilian at development time (see Dual-use technology and military conversion risk).

Five practical steps

If I had to pick one checklist item, it would be Step 1.

Step 1: Build a classification map of your AI

Inventory internal AI systems/products. Map which Annex III fields and which GPAI / systemic-risk GPAI tiers may apply. Leave gray zones explicit rather than forcing a clean label.

Step 2: Revisit EU market-access plans

For products with EU revenue or planned EU revenue, plan against two anchors: Article 50 transparency duties from 2 August 2026, and — where the product is high-risk — conformity assessment, CE marking and database registration from 2 December 2027 (Annex III type) or 2 August 2028 (Annex I type). If the timeline fails, reconsider launch dates or narrow use cases out of high-risk scope.

Step 3: Record training compute (FLOPs)

If you train large models, you need continuous total training FLOPs logging and reporting. When the 10^25 threshold is reasonably foreseeable, the two-week Commission notification duty activates.

Step 4: Define a simultaneous four-layer check procedure

Create an internal procedure that checks EU AI Act, EU Dual-Use Reg, U.S. EAR, and Japan FEFTA at once. Siloed departments leak risk; appoint one cross-functional owner.

Step 5: Institutionalize human-rights due diligence

Article 5 catch-all fires once "reasonable suspicion" arises. Standardize end-user purpose checks, initial human-rights screening, and record retention.

What TRAFEED can do

If four-layer daily checks feel unrealistic, consider TRAFEED (formerly ZEROCK ExCHECK), TIMEWELL's export-control AI agent:

  • Whether counterparties and end users hit Entity List / MEU List / SDN List / Japan's Foreign User List
  • Whether items hit EU Annex I / 500 series, U.S. ECCNs, or Japan's goods ordinances
  • Probability that use cases map to Annex III high-risk fields or Article 5 catch-all
  • Consistency with METI guidelines and notices

Final legal interpretation always stays with humans (internal owners, counsel, customs specialists). Value is in reducing missed signals, shortening review time, and leaving audit trails.

With AI Act compliance consuming headcount in 2026, cutting export-control friction has clear ROI.

Customer feedback

One trading company reported that four-layer checks (AI Act × Dual-Use × EAR × FEFTA) that averaged three days per deal fell to as little as two hours after TRAFEED. Teams with only one or two export-control owners can use it as infrastructure through the AI Act peak.

FAQ

Q1. Does a Japanese SaaS AI service used by EU customers fall under the AI Act?

A. Yes. Under Article 2's extraterritorial clause, if outputs are used in the EU, the provider is in scope. Transparency duties for generative AI and chatbots (Article 50) apply from 2 August 2026. Where the use is high-risk, conformity assessment and appointment of an EU authorised representative (Article 22) apply from 2 December 2027 (Annex III type) or 2 August 2028 (Annex I type).

Q2. We don't know if our in-house LLM exceeds 10^25 FLOPs. What should we do?

A. Calculate and log total training compute. Once the threshold is reasonably foreseeable, notify the Commission within two weeks (Article 52). Designate a single AI Office contact (often legal/compliance).

Q3. Are AI Act "high risk" and Dual-Use "cyber-surveillance" the same thing?

A. They overlap but are not identical. AI Act equals product safety for sale/use inside the EU. Dual-Use equals export licensing from the EU to third countries. An EU-market face-recognition system needs AI Act high-risk compliance (CE mark, etc.) and Dual-Use licensing on export to third countries.

Q4. Is military AI outside the AI Act?

A. Pure military systems are out of scope (Article 2(3)); dual-use systems placed on the market are in scope. The military-only boundary is fuzzy. Most AI systems should be treated as dual-use until proven otherwise.

Q5. What applies when re-exporting AI-related items from an EU subsidiary to a third country?

A. If the EU subsidiary is the exporter, Dual-Use Reg 2021/821 licensing sits with the subsidiary. Japan HQ still faces FEFTA service-transaction (technology) licensing and group-governance duties. Local EU counsel and Japan HQ export control must work together.

What Regulation (EU) 2026/1744 actually changed

The AI Act amendment carried by the Digital Omnibus is already law. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published as OJ L 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. Any description of it as "a provisional political agreement" or "awaiting formal adoption" is out of date.

Three practical points:

  • The general application date did not move. The second paragraph of Article 113 ("It shall apply from 2 August 2026") is unamended.
  • High-risk AI dates moved back. Annex III type (Article 6(2)) applies from 2 December 2027; Annex I type (Article 6(1)) from 2 August 2028. Articles 22, 25, 26 and 27 activate on the same dates.
  • The transitional test for existing systems is now tied to the Chapter III dates. Under the amended Article 111(2), high-risk AI already placed on the market is caught only where there are "significant changes in their designs" after the Chapter III application date. The reference point is no longer a fixed 2 August 2026 but 2 December 2027 / 2 August 2028.

Separately, 2 December 2026 brings the new prohibitions (Article 5(1)(ba), 5(1)(bb), and Article 5(1a)(1b)) and is also the Article 111(4) deadline: providers of synthetic-content generating AI placed on the market before 2 August 2026 must comply with Article 50(2) by that date. That is not a change to the application date of Article 50 itself.

International frameworks moving in parallel

The multi-layer EU–U.S.–Japan structure described here continues to intensify as of July 2026. The 16th Japan–India Annual Summit on July 2, 2026 produced a joint economic-security declaration across semiconductors, critical minerals (rare earths), clean energy, ICT (subsea cables), and pharmaceuticals, with roughly ¥2 trillion in investment framed (Japan–India summit joint press conference (Prime Minister's Office, July 2026)). AI and advanced-semiconductor supply chains are being reorganized in a security frame, which makes "which partners, which items, which destinations" harder. The AI Act application dates are settled by Regulation (EU) 2026/1744 as set out above; on top of that, these international frameworks need tracking in parallel. Details: Japan–India Summit 2026 and economic security.

If you want to tighten export-control operations or cut classification cycle time, review the TRAFEED service catalog (PDF) or contact us.

Key takeaways

The AI Act and Dual-Use Regulation are separate instruments, but in practice they need the same operational lens:

  • 2 August 2026 is the general application date. What starts then: Article 50 transparency duties, the Articles 40–49 conformity-assessment / CE-marking / registration framework, and Article 101 (the Commission's GPAI fining power)
  • Substantive high-risk obligations apply from 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type), as set by Regulation (EU) 2026/1744
  • Fines for prohibited practices reach €35 million or 7% of worldwide annual turnover, whichever is higher
  • Annex III high-risk fields largely overlap Dual-Use cyber-surveillance items in practice
  • GPAI above 10^23 FLOPs; systemic-risk GPAI above 10^25 FLOPs
  • U.S. ECCN 4E091 / GP10 and Japan FEFTA catch-all reform create a four-layer stack
  • Typical Japanese scenarios: EU high-risk AI supply; third-country re-export; fuzzy military exclusion
  • Practice path: inventory, market-access plan, FLOPs logging, four-layer procedure, human-rights DD

If you only do one thing, build a one-page map of your AI. The general application date is 2 August 2026; the substantive high-risk obligations land on 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type). "We don't handle military items" or "we don't export AI" will increasingly fail.

Related articles

  • Complete guide to the EU Dual-Use Regulation 2025 amendment (2025/2003)
  • AI Diffusion Rule withdrawal and alternatives
  • How EAR, China, and EU export controls hit at once
  • Dual-use technology and military conversion risk
  • Export-control changes in 2026

About TRAFEED

TRAFEED (formerly ZEROCK ExCHECK) is an AI agent that reduces missed signals for export-control teams. It checks counterparties, items, and use-case risk across the EU AI Act, EU Dual-Use Regulation, U.S. EAR, and Japan’s FEFTA. 2026 is a good year to cut export-control load while AI Act work peaks.

Three entry points:

  • 30-minute online consultation: whether your AI products may hit Annex III fields or systemic-risk GPAI, plus TRAFEED fit
  • AI Act quick relevance check: a one-page report mapping major products to Annex III, GPAI thresholds, and Article 5 catch-all
  • Product demo: live UI for four-layer checks (AI Act, Dual-Use, EAR, FEFTA)

Details and booking: TRAFEED product page.

References

  1. Regulation (EU) 2024/1689 (AI Act text)
  2. Regulation (EU) 2026/1744 (amending act; adopted 8 July 2026, published as OJ L 2026/1744 on 24 July 2026, in force 27 July 2026)
  3. AI Act Service Desk — European Commission
  4. Annex III: High-Risk AI Systems
  5. Article 99: Penalties
  6. Regulation (EU) 2021/821 (Dual-Use Regulation)
  7. Guidelines on Cyber-Surveillance Items (October 2024)
  8. 2025 Update of EU Dual-Use Control List
  9. Guidelines for GPAI Providers (July 2025)
  10. Framework for Artificial Intelligence Diffusion — Federal Register
  11. METI — Trade Control
  12. CISTEC — Overview of Japanese Export Control Legal Framework
  13. Anderson Mori & Tomotsune — Major Changes to Catch-All Export Controls
  14. Akin — EU Updates Dual-Use Export Control List
  15. SIPRI — EU Catch-All Control on Cyber-Surveillance Exports
  16. WilmerHale — European Commission Issues Guidelines for GPAI Providers

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Contact About TRAFEED
Contact About TRAFEEDContact form (about 3 min)TRAFEED product briefFeatures & rollout in PDF

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

See all materials

Related Knowledge Base

Export Control Guide

Solutions

Strengthen Export ComplianceStreamline compliance with complex export regulations

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Contact UsDownload Catalog

Related Articles

What the EU AI Act Actually Is — The First Thing Exporters to Europe Should Check

What the EU AI Act Actually Is — The First Thing Exporters to Europe Should Check

A plain-language guide to the EU AI Act (Regulation (EU) 2024/1689) written for export-control professionals with no background in AI regulation.

2026-08-01
AI Governance 2026: Five Category Leaders to Know Before the Regulatory Storm Hits

AI Governance 2026: Five Category Leaders to Know Before the Regulatory Storm Hits

The era of "let's use AI to be more efficient" has quietly moved on. 2026 is the year we are being asked how we manage AI.

2026-05-11
Washington Pushes Back on Apple Buying Chinese Memory: Section 5949 and the Supplier Fallout

Washington Pushes Back on Apple Buying Chinese Memory: Section 5949 and the Supplier Fallout

In August 2026, Commerce Secretary Lutnick said the administration opposes Apple sourcing Chinese memory. Here are the Senate and House letters, where CXMT and YMTC actually sit in US regulation, and what Section 5949 and the pending FAR rule mean for component suppliers in Japan and elsewhere.

2026-08-15
What Japan's Foreign Interference Prevention Act and Foreign Intelligence Collection Act Would Change

What Japan's Foreign Interference Prevention Act and Foreign Intelligence Collection Act Would Change

On August 5, 2026, the LDP's Intelligence Strategy Headquarters released its second set of recommendations on strengthening Japan's "information defense capability." Here is what the three pillars of deterrence, collection, and oversight actually contain, read against the statutory text.

2026-08-15
What transshipment actually is. Why a White House report named Japan

What transshipment actually is. Why a White House report named Japan

On 13 August 2026 the White House published a 25-page report on illegal transshipment. Headlines led with $75 billion, 450,000 jobs, and Japan. The primary text puts Japan in Tier 1 for the scale of legitimate trade, not because a scheme was pinned to a Japanese city. This column reads the estimates and the enforcement that follows.

2026-08-14
Reading the Detentions in China: The Gap Is the Other Country's Export Controls

Reading the Detentions in China: The Gap Is the Other Country's Export Controls

Several Japanese nationals have been reported detained in China, in connection with suspicion relating to export controls on dual-use items including rare earths. Starting from the premise that detention is not a finding of guilt, this sets out the gap most companies have — watching their own country's export controls but not the counterparty country's — and what to decide in advance.

2026-08-12