Generative AI and Export Controls: 20 FAQs
I am Ryuta Hamamoto from TIMEWELL.
"We want to have a generative AI tool summarize our engineering drawings — would that violate export control law?" Over the past year, this has become the single most common question I receive. Not long ago, export control consultations centered on how to prepare classification documents or use bulk licenses. Now the questions are overwhelmingly about generative AI. With ChatGPT and Claude in everyday use on the shop floor, that shift was inevitable.
Regulators are moving too. In Japan, an amendment to the Export Trade Control Order (Cabinet Order No. 376 of 2025, promulgated November 14, 2025) took effect on February 14, 2026, bringing FPGA-based equipment — a category of AI-related hardware — under control. In the United States, the AI Diffusion Rule, which attempted to control AI model weights directly, was rescinded on May 13, 2025, and a final rule effective January 15, 2026 reset the license review posture toward China. Six-month-old articles in this space are already stale. That is the pace we are dealing with.
This article answers 20 questions on generative AI and export controls, each verified against primary sources.
Usage policy and approval templates for generative AI: Templates that save you from drafting the internal rules discussed in Q16–Q19 from a blank page — an adoption proposal plus a 10-article usage policy that codifies which information must not be entered and how outputs are handled, aligned with the Personal Information Protection Commission alert of 2 June 2023. The export-control specifics (the three information tiers in Q17, alignment with your existing internal compliance programme in Q19) still need to be written over the top, but the structure of the clauses is already there. → Download the Generative-AI Adoption Proposal & Usage Policy Templates (Free. Your company name and work email address are required.)
The Short Answer: A Quick-Reference Table
Before diving in, here are five common scenarios and the practical bottom line. Feel free to start with the row closest to your situation.
| Scenario | Export control issue | Practical bottom line |
|---|---|---|
| Entering drawings or specifications into an overseas cloud AI service | Whether it constitutes "provision of technology" under Article 25(1) of the Foreign Exchange and Foreign Trade Act | Input and processing for self-use generally does not qualify as a regulated service transaction. Contracts allowing training use or overseas staff access require individual review |
| Foreign-national employees or secondees accessing technical materials in an AI tool | Deemed exports (specific categories) | Providing controlled technology to a person in a "specific category" can require a license even if they are a resident (clarified rules effective May 1, 2022) |
| Providing trained AI model weights overseas | U.S. ECCN 4E091 was rescinded; advanced chip controls remain | Check EAR reexport rules if U.S.-origin technology is involved; classification under Japanese law as a program or technology still applies |
| Using AI for export classification work | Where final responsibility sits | AI does the groundwork; humans make the final call, with reasoning and logs retained |
| Rolling out cloud LLMs company-wide | Consistency with internal policies and your compliance program (CP) | Codify input restrictions and contract checks before deployment |
The rest of this article unpacks each row. If you are reviewing your classification or screening workflow as a whole, the TRAFEED product catalog (PDF) is also available.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Does Entering Data into Generative AI Count as "Provision of Technology"? (Q1–Q6)
Q1. Does entering drawings or specifications into a generative AI tool amount to an "export" by itself?
As a rule, no. Article 25(1) of the Foreign Exchange and Foreign Trade Act regulates transactions that provide specified technology to non-residents and certain others. METI's service transaction notification — amended effective September 1, 2013 to address cloud computing — defines "provision" as placing technology in a state where others can use it. Under METI's published interpretation, storing information on a provider's server purely for your own use does not constitute a regulated service transaction and requires no license.
Generative AI goes a step beyond storage — it processes your input — but the analytical axis is the same. If the AI processes data solely for your own business and your technical data is never placed where others can use it, the transaction falls outside the regulated category. The problem is placing data in that state without realizing it, which is what Q2 covers.
Q2. In what situations could input become a regulated "provision of technology"?
Three patterns deserve attention. First, contracts under which your inputs are used to train the provider's models. Technology absorbed into training data can surface in outputs available to users worldwide, and that state carries the risk of being treated as placing technology where others can use it. Second, contracts allowing the provider's overseas staff to view inputs for maintenance or moderation. Third, sharing features — links or shared workspaces — that expose content to non-residents or to persons in the specific categories discussed below.
In its security export control Q&A, METI lists four checkpoints for placing technical information on overseas servers: the sensitivity of the information, the contract terms, the security level, and the physical location of the servers. Those four checkpoints translate directly to generative AI. Contract terms deserve particular care, because training-use provisions differ dramatically between free plans and enterprise agreements. Skipping the terms of the actual plan in use is the single most common gap I see.
Q3. How do we determine whether the information we input is listed controlled technology?
That is a technology classification exercise — determining whether the information falls under the technology entries (including programs) of the appended tables of the Foreign Exchange Order. What matters is not the drawing as an artifact but the design information and manufacturing conditions it contains. Tuning parameters for semiconductor manufacturing equipment, molding conditions for carbon fiber, cryptographic source code — information of this kind should be treated as potentially controlled until confirmed otherwise.
Conversely, providing technology already in the public domain requires no license. Article 9(2)(ix) of the Ministerial Ordinance on Trade Relation Invisible Trade lists publicly known technology as a license exception, covering catalogs, published patents, and academic journals. In other words, "may we input this into generative AI?" ultimately reduces to the classification of the information itself. A specification table from a public catalog needs no special handling; detailed internal design data needs classification first.
Q4. What is a deemed export, and how does it relate to generative AI?
A deemed export treats the provision of technology to a non-resident inside Japan the same as an export. The clarified rules that took effect on May 1, 2022 broadened the scope: providing sensitive technology to a resident who falls into one of three "specific categories" is now also regulated. The categories are persons under the direction of a foreign government or foreign entity through an employment or similar contract, persons receiving 25% or more of their annual income from a foreign government or entity, and persons acting in Japan under the instructions of a foreign government.
The connection to generative AI is the internal knowledge base. If you build a system that makes technical documents searchable through an LLM, a state in which an employee in a specific category can retrieve sensitive technology from it raises deemed-export questions. Export control should have a seat at the table when access rights are designed. For a practical walkthrough of the specific categories, see our guide to deemed exports and the specific categories.
Q5. What is the risk when employees use personal generative AI accounts?
This is shadow AI. Free consumer plans often default to using inputs for model training, and they are a different animal from enterprise contracts. The principle — no business data outside company-approved tools — is usually framed as an information security matter, but export control analysis reaches the same conclusion, and with a criminal statute behind it, it tends to carry more weight with management. Prohibition alone will not hold, though. The realistic approach is to provide an approved enterprise tool and codify the rules, which Q16 onward addresses.
Q6. What should we watch for when sharing generative AI tools with overseas sites?
Transmitting technical data to an overseas site is an ordinary technology provision, generative AI or not. Employees of overseas subsidiaries are in principle non-residents, so placing listed controlled technology in a shared workspace triggers a license analysis. The counterpart country's law stacks on top. For U.S. sites, the Export Administration Regulations' deemed export rules — controls on disclosing technology to foreign nationals inside the United States — can apply separately. A global AI platform needs to be designed with both Japanese law and each local regime in view.
Export Controls on AI Models Themselves: U.S. Developments, 2025–2026 (Q7–Q10)
Q7. Are trained AI model weights themselves controlled? (United States)
They very nearly were. On January 15, 2025, the U.S. Commerce Department's Bureau of Industry and Security (BIS) published the interim final rule "Framework for Artificial Intelligence Diffusion" (90 FR 4544), creating ECCN 4E091 to control the weights of closed-weight AI models trained with more than 10^26 floating-point operations. It was an ambitious framework that sorted the world into three tiers under a comprehensive licensing regime.
Then, on May 13, 2025 — two days before the May 15 compliance date — BIS announced the rule's rescission, citing burdens on innovation and strained relations with partner countries. The comprehensive licensing regime for model weights never took effect.
Q8. If the rule was rescinded, can we stop worrying about AI model exports?
No. What was rescinded is the comprehensive licensing regime for model weights. The underlying controls on advanced AI chips (ECCN 3A090 and related entries) remain in force. On the same day as the rescission announcement, BIS issued three guidance documents: a warning that using certain PRC advanced-computing chips, including specific Huawei Ascend models, can violate the EAR; a warning about U.S.-origin AI chips being used to train Chinese AI models; and guidance on protecting supply chains against diversion.
My reading is "framework rescinded, enforcement sharpened." The predictability of a comprehensive regime is gone, replaced by case-by-case enforcement pressure. From a company's perspective, the rulebook got thinner while the penalty risk stayed — which arguably makes compliance harder, not easier.
Q9. What has changed in 2026?
The headline is the BIS final rule effective January 15, 2026. The license review policy for advanced AI chips destined for China and Macau shifted from a presumption of denial to case-by-case review under strict conditions. The eligible range covers chips with total processing performance (TPP) below 21,000 and DRAM bandwidth below 6,500 GB/s — roughly up to the level of NVIDIA's H200 and AMD's MI325X. Frontier-class chips stay restricted; one generation back can now clear review under conditions. It is a recalibration of the balance between control and commerce.
Meanwhile, a comprehensive successor to the AI Diffusion Rule has not been published as of July 2026. BIS has signaled a "stronger but simpler" replacement without committing to a timeline. Companies handling AI models or AI chips should keep a standing process — quarterly at minimum — for monitoring BIS developments.
Q10. How does Japan regulate AI models and AI-related items?
Japanese law has no control entry that names AI model weights as such. But AI models are programs and technology, so depending on capability and use they can fall under existing entries of the appended tables — image analysis models with military applications and cryptographic software are the typical examples. "No AI-specific entry, therefore out of scope" is a misreading; classification proceeds within the existing framework.
On the hardware side, things did move. The amendment to the Export Trade Control Order effective February 14, 2026 (Cabinet Order No. 376 of 2025, promulgated November 14, 2025) created a new entry — Appended Table 1, item 7(10-2) — covering modules, assemblies, and equipment incorporating FPGAs, with a threshold of 1,800,000 total LUT inputs. For the full picture, see our complete guide to the February 2026 amendment.
Using AI for Export Classification: Accuracy and Responsibility (Q11–Q15)
Q11. Can export classification be fully automated with AI?
No — and I will state that without hedging. Export classification is not form-filling; it is a judgment task involving legal interpretation, and under the Foreign Exchange and Foreign Trade Act, the exporter bears that responsibility. However capable AI becomes, the locus of responsibility does not move.
That said, decomposing the work reveals plenty of AI-friendly steps: matching product specifications against the technical parameters in ministerial ordinances, translating between commercial and legal vocabulary (recognizing a "3D printer" as an "additive manufacturing machine"), narrowing candidate control entries, and citing the underlying provisions. This groundwork consumes most of a practitioner's time. Delegate it to AI and let humans concentrate on interpretation and the final call — that division of labor is the realistic answer. Our article on automating export classification with AI covers the workflow in more depth.
Q12. How accurate is AI-based export classification?
Separate the clearly-controlled and clearly-not-controlled cases from the gray zone where interpretation is contested. AI accuracy is strong in the former; the latter requires human judgment, full stop. Our product TRAFEED confirmed AI classification accuracy of 95% or higher in a joint validation study with Okayama University (company research) and holds Japanese Patent No. 7862062 for its classification method. Even so, our operational design always includes a human approval step. The 95% figure means "reliable enough as groundwork that humans then verify" — not that the remaining 5% can be ignored.
Q13. What about hallucination — AI producing incorrect determinations?
The risk is real. A general-purpose LLM used as-is will sometimes cite control entries that do not exist or transpose numeric parameters from the ordinances. In export control, that class of error can flow straight into an unlicensed export.
The countermeasures come in two layers. First, RAG — retrieval-augmented generation — so the AI answers only after retrieving the current regulatory text rather than relying on its training memory. Second, multi-LLM consensus: multiple models classify independently, results are reconciled, and disagreements route to human review. TRAFEED adopts this multi-LLM consensus approach. Raising the probability that one model's miss is caught by another is unglamorous probability engineering, but it works.
Q14. How should an AI-assisted classification workflow be structured?
Insert AI steps into your existing flow rather than replacing it. A five-step structure that works well in practice:
- Structure the product information — model numbers, specifications, intended use, and components in a classification-ready form
- AI first-pass screening — the AI narrows candidate control entries and cites the provisions and notifications behind each
- Parameter verification — specifications are matched against the numeric thresholds, and the practitioner verifies the AI's citations against the original text
- Human final determination and approval — gray-zone cases escalate to senior reviewers or outside experts
- Preparation of the classification document and retention of logs, including the AI's cited reasoning
Step 3 is the one to protect. Even when the AI says "not controlled," the practitioner checks the cited provision in the original text. Skip that single step and hallucinations flow straight into your classification records.
Q15. Can AI determinations serve as evidence in audits or regulator inquiries?
Do not rely on a standalone AI determination as your basis. Preserve the form "the responsible person made the determination with AI support." That said, AI adoption tends to strengthen audit readiness rather than weaken it. The provisions the AI referenced, the parameters it matched, and the path to the conclusion are all captured in logs, so "why did you determine this was not controlled?" gets a documented answer. Reasoning that used to live only in a practitioner's head becomes externally explainable — which also aligns with the compliance standards expected of exporters regarding classification procedures.
Designing Internal Policies for Cloud LLM Use (Q16–Q19)
Q16. What should the internal policy cover at minimum?
Seven items. One: a classification scheme for prohibited inputs (detailed in Q17). Two: designation of approved services and plans, with an explicit ban on personal accounts for business use. Three: mandatory opt-out from training use. Four: a review procedure at contract renewal, because training clauses and server locations change with contract amendments — check annually. Five: access management that accounts for employees in the specific categories. Six: retention and periodic inspection of input logs. Seven: recurring training.
The ordering is deliberate: classification and tool designation first, logs and education after. A policy that is nothing but prohibitions will not survive contact with the field, so pair the restrictions with an approved tool people can actually use.
Q17. How should prohibited inputs be classified?
Anchor the information classification to export classification. The three-tier scheme we recommend:
| Tier | Examples | Generative AI input |
|---|---|---|
| Tier A (controlled technology) | Technical data that is or may be listed controlled technology — detailed design drawings, manufacturing conditions, cryptographic source code | Prohibited. If handled at all, only in a closed environment with no training use, domestic processing, and access controls |
| Tier B (confidential, not controlled) | Confidential information confirmed not controlled through classification — sales materials, non-controlled specifications | Approved enterprise services only |
| Tier C (public information) | Public catalogs, published patents, press releases | No restriction |
The load-bearing detail is that Tier A includes "may be" controlled. Technical data that has not yet been classified stays in Tier A until classification is complete. That is the insurance against "it's probably fine" inputs of unassessed information.
Q18. How should we phrase due-diligence questions to AI vendors?
Add a handful of export control questions to your standard pre-contract security review. A template you can use directly:
From the standpoint of security export control under the Foreign Exchange and Foreign Trade Act, we would like to confirm the following about your service. (1) Is data we input ever used to train your models or those of third parties? If so, how can this be disabled contractually or via settings? (2) In which countries are the servers storing our input data physically located? (3) Could your employees or subcontractors access our input data? If so, from which countries and for what purposes? (4) What are your data retention periods and deletion procedures?
Get the answers in writing. In a later audit or regulator inquiry, being able to show "we verified before adopting" is what counts.
Q19. How should this integrate with our existing export compliance program (CP)?
Folding generative AI into your existing CP is more durable than a standalone policy. A CP normally prescribes pre-checks for technology provision; add a clause stating that entering technical information into cloud services or generative AI is treated as a technology provision and governed by the Q17 tiers, then attach the usage guideline as an appendix. CISTEC's reference materials on export compliance programs are useful when drafting the clause. And a policy is not the deliverable — the recurring training and log inspections from Q16 are what keep it alive.
Getting Started (Q20)
Q20. So where should we actually start?
Three stages. First, a shadow AI inventory: until you know which teams are putting what information into which tools, any policy is theoretical. Second, codify the rules — fold the seven items from Q16 into your CP and stand up an approved tool. Third, bring AI support into export classification and counterparty screening, the two workflows where volume and repetitiveness make AI's impact most visible.
TRAFEED provides multi-LLM consensus classification support and counterparty screening, and is already in use at more than 20 organizations. If you would like to discuss how to structure export control for the generative AI era — demo in hand — contact us.
Summary
- Entering technical data into generative AI for self-use generally falls outside regulated service transactions, but training-use clauses and overseas access can turn it into a "provision of technology"
- An internal AI platform accessible to employees in the specific categories raises deemed-export issues (rules clarified effective May 1, 2022)
- The U.S. control on AI model weights (ECCN 4E091) was rescinded on May 13, 2025, but advanced chip controls remain, and the rule effective January 15, 2026 moved China-bound reviews to conditional case-by-case
- Classification AI works as a hybrid: RAG, multi-LLM consensus, human final approval, and retained logs are the pillars of accuracy
- Build the internal policy around the three-tier input classification, folded into your existing CP
Both the regulations and the technology keep moving, and we will keep this article updated. Start with the shadow AI inventory — that alone will change how the risk looks.
References
- METI, "Clarification of Deemed Export Control" (effective May 1, 2022): https://www.meti.go.jp/policy/anpo/anpo07.html
- METI, Q&A on the Clarification of Deemed Export Control: https://www.meti.go.jp/policy/anpo/law_document/minashi/minashiqa3.pdf
- METI, "Cabinet Approval of the Order Amending the Export Trade Control Order" (November 11, 2025): https://www.meti.go.jp/press/2025/11/20251111001/20251111001.html
- METI, Security Export Control Q&A (technology): https://www.meti.go.jp/policy/anpo/qanda25.html
- CISTEC, "Amendment of the Service Transaction Notification Regarding Cloud Computing": https://www.cistec.or.jp/service/cloud.html
- e-Gov, Ministerial Ordinance on Trade Relation Invisible Trade: https://laws.e-gov.go.jp/law/410M50000400008/
- Federal Register, "Framework for Artificial Intelligence Diffusion," 90 FR 4544 (January 15, 2025): https://www.federalregister.gov/documents/2025/01/15/2025-00636/framework-for-artificial-intelligence-diffusion
- BIS, "Department of Commerce Announces Rescission of Biden-Era Artificial Intelligence Diffusion Rule" (May 13, 2025): https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens
- Morgan Lewis, "BIS Revises Export Review Policy for Advanced AI Chips Destined for China and Macau" (January 2026): https://www.morganlewis.com/pubs/2026/01/bis-revises-export-review-policy-for-advanced-ai-chips-destined-for-china-and-macau






