TRAFEED

Does letting someone use a GPU over the network count as an export? The RASA bill, and whether Japan has the same gap

Published2026-08-21Ryuta Hamamoto

You can stop the chip from leaving the country, but you cannot stop someone from using it over a network connection. This piece traces where that difference comes from, working from the text of the EAR, BIS's own advisory opinions, and the Japanese Foreign Exchange and Foreign Trade Act. It covers what the RASA bill actually says, whether Japan has the same gap, and what to check in practice.

Does letting someone use a GPU over the network count as an export? The RASA bill, and whether Japan has the same gap
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

An export control manager asked me a question the other day that I have not been able to stop thinking about. "We go to enormous lengths to stop chips from leaving the country. So why is nothing stopping someone overseas from just using those chips over a network connection?"

It is a fair question, and once you start digging, it stops being an American problem. Building data centers in Japan and selling compute to overseas customers is a real and growing business here.

The short answer: renting out compute is not covered by export controls, in the U.S. or in Japan. But that is very far from saying the cloud is unregulated. There is a fairly sharp line between what is covered and what is not, and it is worth tracing that line through the actual text.

The short version

  • The EAR's definition of "export" (15 CFR §734.13) requires something to move, or technology or source code to be disclosed. Running a calculation does neither
  • This is not a matter of interpretation. BIS answered it in writing in 2009: providing computational capacity is not subject to the EAR, and the provider does not even need to ask the customer's nationality
  • RASA has passed the House twice and stalled in the Senate both times. It is not law
  • RASA does not change the definition of "export." It creates a parallel category called "remote access," and most coverage gets this wrong
  • Japan has the same gap. The decisive text is the definition of "goods" as movable property, and servers do not move
  • But software you serve on top of that compute can be caught. Japan's services circular already separates storage from SaaS
  • Reported third-country arrangements are not illegal under current rules. Writing "evasion" or "circumvention" misstates the facts

Why the EAR cannot reach it

The definition of "export" has no room for computation

The EAR defines "export" at 15 CFR §734.13.1 There are three limbs: an actual shipment or transmission out of the United States; releasing technology or source code to a foreign person in the United States (a deemed export); and transferring registration, control, or ownership of certain spacecraft.

Every one of them requires either something crossing a border or technology being disclosed to a person. Letting a GPU run a job does neither.

Worth noting: this definition has not changed since June 2016. The text predates the creation of ECCN 3A090 and 4A090, the entries written specifically for AI chips.

Deemed exports are limited twice over

The natural follow-up is whether letting a foreign national use the machine is a deemed export. Two limits get in the way.

What can be released is limited. Only technology and source code count. The regulation goes out of its way to say "but not object code." Renting a GPU transfers neither.

Where the person stands is limited. That limb requires the foreign person to be "in the United States." Someone connecting from Shenzhen falls outside the text before you even reach the merits.

Reinforcing this, §734.15 defines "release" as visual or other inspection of technology by a foreign person, or oral or written exchange of technology with one. It is written to catch showing someone how the chip works, not letting the chip do arithmetic.

A common misreading: "§734.18 has a cloud carve-out"

It does not. §734.18(a)(5) says that sending, taking, or storing your own technology or software is not an export if it is unclassified, secured with end-to-end encryption using FIPS 140-2 compliant modules, and not intentionally stored in a D:5 country. That is about keeping your own encrypted data across borders. It is not about borrowing compute.

The word "cloud" never appears in §734.18. BIS has said as much publicly: the term is not used in the regulatory text.

The decisive source is BIS itself

Everything above is textual reading. But there is a much more direct answer, because BIS addressed this head-on in an advisory opinion dated January 13, 2009.2

The answer to Question 1 is the heart of it:

The service of providing computational capacity would not be subject to the EAR as the service provider is not shipping or transmitting any commodity, software, or technology to the user.

Question 5 goes further:

the service provider is not required to inquire about the nationality of the customer.

No duty even to ask. That opinion is still listed in BIS's advisory opinion index and has not been withdrawn. Follow-on opinions from 2011 and 2014 take the same position.

One carve-out deserves mention for accuracy. Question 2 of the same opinion notes that even a service outside the EAR may still be caught by §744.6(a)(2) if the provider knows it will assist activities described there. But §744.6(a)(2) covers missile and chemical or biological weapons activity. Advanced computing and AI are not in it.

BIS acknowledged the gap and deferred

There is a revealing exchange in the Federal Register from October 25, 2023.3

A commenter argued that IaaS could undermine the supercomputer controls and asked BIS to clarify its intent in light of the 2009 and 2011 opinions. BIS replied:

BIS is also concerned regarding the potential for China to use IaaS solutions to undermine the effectiveness of the October 7 IFR controls and continues to evaluate how it may approach this through a regulatory response.

Handed a direct opportunity to repudiate those opinions, BIS did not. In the same rule it asked commenters what additional controls or requirements might be needed, a question that only makes sense if the existing ones do not reach.

Congress reached the same conclusion. The House Select Committee on the CCP put it plainly in an April 2026 report:4

And restrictions on accessing such chips through the cloud are non-existent.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What RASA actually says

RASA, the Remote Access Security Act, is the attempt to close that gap. It looks quite different from how it is usually described.

The record

Congress Bill Sponsor Introduced House floor Status
118th H.R. 8152 Rep. Lawler (R-NY-17) April 29, 2024 Passed September 9, 2024 (voice vote) Died in Senate Banking
119th H.R. 2683 Rep. Lawler (R-NY-17) April 7, 2025 Passed January 12, 2026, 369–22 In Senate Banking
119th (Senate) S. 3519 Sen. McCormick (R-PA) December 17, 2025 None No action since referral

Two House passages, two stalls in the Senate. In the January 2026 roll call, Republicans split 167–22 and Democrats went 202–0. All 22 no votes were Republican.

Misreading one: the definition of "export" does not change

Plenty of write-ups say RASA treats remote access as an export. That is not what it does.

RASA amends the Export Control Reform Act, but it leaves "export" alone. Instead it creates a parallel category, "remote access," and threads it through the President's control authorities, the additional authorities, licensing, penalties, and enforcement.

Here is the definition from the House-passed text:5

the term 'remote access' means access on a purposeful, knowing, reckless, or negligent basis to an item subject to the jurisdiction of the United States under this Act by a foreign person through a network connection, including the internet or a cloud computing service, from a location other than where the item is physically located if the Secretary determines that the use of the item could pose a serious risk to the national security or foreign policy of the United States.

Cloud providers themselves are pulled in by four words inserted into the authorities: "or remotely access (including the provision thereof)." Not just the person reaching in, but the person offering the door.

The distinction has practical bite. Building a separate category rather than expanding an existing one means existing license exceptions and carve-outs do not automatically carry over.

Misreading two: it is not limited to countries of concern

You will also read that RASA targets China, Russia, Iran, and North Korea. The House-passed text does not.

Items Persons Risk test
2024 House-passed CCL items, regardless of physical location any foreign person enumerated
2026 House-passed (current) items subject to ECRA jurisdiction any foreign person general "serious risk" plus mens rea
Senate S.3519 (no action) CCL items foreign persons of concern only enumerated, plus "has demonstrated"

Only the Senate bill has a country limitation. The House text says "a foreign person," full stop.

It gets confusing because on the House floor on January 12, 2026, a member described the bill as covering "foreign persons of concern, specifically those from Russia, Iran, North Korea, and China." The passed text says no such thing. The floor description and the enrolled text diverge, and secondary coverage has copied the error. When scope matters, read the text.

One more drafting note: the 2024 version said "without regard to the physical location of the item," which would have reached chips sitting in U.S. data centers. That phrase is gone from the 2026 version.

Where the opposition actually is

Honestly, there is almost no organized opposition in the record. The committee vote was 51–0, the floor vote 369–22 with zero Democratic no votes, and nobody spoke against it on the floor in either Congress.

That does not mean nobody is worried. The concern shows up in the drafting history rather than in speeches. The bill gets narrower every time it moves.

  • The 2024 floor amendment replaced a broad catch-all definition with CCL-linked items and enumerated risks
  • The 2026 floor amendment added a mens rea standard, a savings clause preserving the criminal burden of proof, a Secretary-determination requirement in place of the catch-all, and a reporting provision on how the regulations may affect the U.S. economy
  • The Senate bill is narrower on every axis: persons of concern only, IaaS pinned to the NIST SP 800-145 definition, a ten-year sunset, and a reporting duty that explicitly calls for maximizing privacy and minimizing compliance costs

The real issue is the reversal of a twenty-year assumption. Cloud providers built their compliance programs around the 2009 opinion. BIS told them in writing that this was outside the EAR and that they did not need to ask about nationality. RASA inverts that.

How to read the recent reporting

Through 2026 there has been a steady stream of reporting about Chinese firms reaching Nvidia compute through data centers in third countries. There is one thing to get right before writing about any of it.

Under current U.S. rules, this is not illegal.

Specialists say so on the record, and the reporting itself describes it as an activity that is not, at present, illegal. U.S. export controls reach the physical chips and not remote access to them, which is exactly what the text above produces.

So "evasion," "circumvention," and "violation" are the wrong words. The accurate phrase is outside the scope of the rules. We hold to that language in our own writing.

Two more practitioner notes.

Avoid naming a company as the subject of a definitive claim. Much of the reporting rests on anonymous sources, and there are no established violations or penalties. The U.S. government has confirmed nothing on the record. One intermediary has stated on the record that its services are fully compliant with all applicable regulations. Among the named firms, one denied a narrow and specific point, another declined to comment, and others have not responded at all. Silence is not a denial, and it is not an admission either.

The circulating numbers need their caveats attached. You will see an estimate that remote access could raise China's access to advanced compute by around 60 percent. Read the original and the author says plainly that this is the lower bound of a range spanning more than an order of magnitude, that changing one assumption about U.S. licensing policy pushes it to roughly four times, and that nobody, including the U.S. government, actually knows the figure. Quoting the 60 percent alone misrepresents the source.

Does Japan have the same gap?

Now the part that matters for readers here. If you let a non-resident use GPUs or a data center located in Japan, do you need a license under the Foreign Exchange and Foreign Trade Act?

In principle, no. Here is the reasoning from the text.

It is not an export of goods

Article 48(1) requires a license for the export of goods. The definition does the work:

Article 6(1)(xv): "goods" means movable property other than precious metals, means of payment, and securities or other instruments embodying claims6

The servers stay where they are. Nothing movable crosses a border, and the analysis stops there.

It is not a provision of controlled technology

Article 25(1) reaches "technology relating to the design, manufacture, or use of" controlled goods. So what counts as technology? Interestingly, neither the ministerial ordinance nor the cabinet order defines it. The definition sits in METI's services circular:7

"Technology" means specific information necessary for the design, manufacture, or use of goods. Such information is provided in the form of technical data or technical assistance.

Technical data means blueprints, specifications, manuals, programs and the like. Technical assistance means instruction, skills training, working knowledge, consulting services.

Renting compute delivers a benefit — processing capacity — that is neither. The appended table to Article 17 of the cabinet order runs to sixteen items, and every one of them is framed as technology relating to goods listed in the export control order. There is no entry for a capability untethered from goods.

Neither the services provision nor the transmission provision applies

The service transactions designated under Article 25(5) are limited to three: processing or storage of mineral products, separation or reprocessing of irradiated nuclear fuel, and treatment of radioactive waste. Compute is not among them.

Article 25(3) is the one provision that reaches network transmission, but it covers "transmission of information constituting controlled technology," not letting someone compute over a link. It is also confined to transmissions from telecommunications facilities located in Japan. A non-resident sending their own data to a Japanese server and pulling results back runs the opposite direction from what the provision contemplates.

The circular already treats storage as out of scope

Appendix 1-2 of the services circular separates two cloud scenarios explicitly.

For storage services, so long as the contract is solely for storing information for the customer's own use, the circular says that even where controlled technology is stored on servers located overseas, this is in principle not a service transaction requiring a license. If storing on an overseas server is out of scope, an arrangement where the data never leaves a Japanese server is not going to be caught by some other route.

But these situations are caught, and they matter

This is the part to pay attention to. Compute itself may be out of scope, but what you serve on top of it may not be.

1. SaaS where the program is controlled technology. Appendix 1-2(2) states that making a program on a server usable without download is a transaction for the purpose of provision. "We do not let them download it" is not a defense. The circular defines provision as placing something in a state where another party can use it, so the moment it is usable, provision has occurred. Preinstalling controlled software on a GPU cloud and letting non-residents use it is the textbook case.

2. Contracting while knowing you can view the customer's controlled technology. The proviso to Appendix 1-2(1) says such a contract is deemed a transaction for the purpose of providing that technology.

3. Support or tuning that amounts to technical assistance. Instruction and transfer of working knowledge are provision of technology in themselves.

4. Engineers transmitting technical data to non-residents. Always live, independent of any cloud question.

So the gap is compute itself, not the cloud generally. "Japanese cloud is unregulated" is simply wrong.

Deemed exports do not close this

Japan's 2022 clarification of deemed exports does not reach here, for three reasons that all come from the text.

First, the specified categories are expressly limited to residents who are natural persons. Deemed export treatment extends provision-to-a-resident into provision-to-a-non-resident; it is aimed at people inside Japan. Non-residents are already covered by Article 25(1) itself.

Second, the amendment expanded who counts as the counterparty, not what counts as the thing provided. The object is still controlled technology. If compute is not controlled technology, the identity of the user does not change the answer.

Third, the circular never uses the words "remote access" or "computing resources."

Deemed exports plug a gap about people, not a gap about compute.

While we are here, the categories themselves are widely misdescribed. They are: a person under the direction of, or owing a duty of care to, a foreign entity or government under a contract; a person receiving benefits from a foreign government amounting to 25 percent or more of annual income; and a person acting in Japan under the instruction or request of a foreign government. Running your program on a vague notion of "under foreign government control" will produce wrong answers.

Japan's critical infrastructure regime does not cover it either

People sometimes ask whether the prior-review regime under the Economic Security Promotion Act picks this up. It does not.

Article 50(1) designates fifteen sectors: electricity, gas, oil, water, railways, trucking, ocean shipping, port transport, aviation, airports, telecommunications, broadcasting, postal services, finance, and credit cards. There is no category corresponding to cloud services or data centers.

Telecommunications looks like the obvious candidate, but two things stand in the way. The cabinet order carves out the businesses listed in Article 164(1) of the Telecommunications Business Act, the third of which is a business providing telecommunications services other than intermediating others' communications, without installing line facilities. Pure IaaS, PaaS, and SaaS generally land there. And the designation criteria are narrow: operators of Category I designated facilities, holders of 10 percent or more of international submarine cable capacity, certified 5G plan holders, and messaging services with 60 million or more users. No cloud or data center operator is designated.

Cloud enters this regime only as a component of critical equipment used by designated operators. The regulated party is the designated operator, not the cloud provider.

While I am at it: ISMAP is not law. It is an assessment and registration scheme for government procurement, not a regime governing private-sector cloud use. The two get conflated often enough to be worth stating.

How the two regimes divide

FEFTA (security trade control) Economic Security Promotion Act, Chapter 3
Protects against technology and goods leaving critical services stopping
Object goods (movable property), controlled technology critical equipment procurement and maintenance outsourcing
Regulated party exporters and technology providers designated critical infrastructure operators
Cloud providers caught if the program served is controlled technology out of scope, except indirectly as component suppliers

One looks at technology going out; the other at domestic infrastructure going down. "Compute that stays put while a foreign national uses it" falls in between.

What the debate in Japan looks like

Is the Japanese government simply missing this? Reading the source documents, I do not think so. The framing is different.

I searched the full text of the interim report from METI's export control subcommittee, published April 2024.8 The words cloud, remote, computing resources, and data center do not appear. What it advanced instead was a different axis:

Concerns about diversion to military use over the passage of time are more pronounced in transactions of technology than in transactions of goods. (...) Measures for strengthened management that focus on technology transactions and take the passage of time into account should be introduced.

That became the public-private dialogue scheme for critical technologies. Not remote access, but a time-based view of technology transfer.

Meanwhile, the Cabinet Secretariat's expert panel recommendation from January 2026 does raise an adjacent issue:9

Measures to protect large volumes of data on data centers and in the cloud (...) measures are needed to protect large volumes of data on data centers and in the cloud from acts conducted from outside our country.

The focus is protecting data, not controlling access to technology, and that is the meaningful difference from the U.S. approach. The same recommendation also applies a brake:

the regulation should be designed so as not to unduly impede business activities such as data center construction, in which investment is currently progressing. Careful and continued consideration of this regulation is therefore necessary.

That regime was not included in the June 2026 amendment and remains under consideration. So the honest reading is not oversight but continued deliberation balanced against investment promotion.

AI policy points the other way entirely. The AI Basic Plan adopted by Cabinet decision in July 2026 refers repeatedly to computing resources and data centers, always in the context of promotion and buildout. Export control does not appear.

One thing I want to be straight about

I have written "in principle not covered" throughout. That is a negative argument.

Neither jurisdiction has text saying compute provision is out of scope. What I have shown is that the elements for being in scope are not met.

The U.S. position rests on firmer ground because of the 2009 advisory opinion, an explicit statement from the regulator. Japan has no equivalent administrative interpretation that I can find. The asymmetry is real and I would rather say so.

In practice, then: work out which side of Appendix 1-2 your arrangement sits on, confirm nothing controlled is preinstalled, check whether your support work has drifted into technical assistance, and confirm your specific case with METI. This is not an area to run on "probably fine."

What to check in practice

For anyone providing compute or SaaS to overseas customers, or planning to:

1. Separate storage from program provision. Appendix 1-2 treats these differently. Renting bare GPUs and serving software on top produce different answers.

2. Classify anything preinstalled. "They cannot download it" is not a reason. Provision is complete once the software is usable. This is the item I see missed most often.

3. Check access rights to customer data in both contract and implementation. Signing while knowing you can view controlled technology triggers the deeming provision. It is worth confirming your architecture does not quietly grant that access.

4. Draw a line around support. Tuning help and technical instruction are technical assistance. Decide internally where operational support ends and technology provision begins.

5. Track live rules separately from pending bills. RASA is not law. But the January 2026 rule revising license review policy for advanced computing already imposes license conditions requiring, among other things, a list of intended IaaS remote end users in specified countries. That one is in force today.

At TRAFEED we follow these developments continuously and support customers with counterparty screening and classification work. Sorting out whether a particular arrangement is caught means grinding through statutory text and circulars line by line, which is where most of the real effort in this field goes. If you have an arrangement you are unsure about, we are happy to look at it.

Wrapping up

  • The EAR's definition of export requires movement or disclosure. Computation is neither, and BIS said so in writing in 2009, including that no nationality check is required
  • BIS acknowledged the gap in the Federal Register in 2023 and deferred a response to future rulemaking
  • RASA has passed the House twice and is not law
  • RASA does not change "export." It creates a parallel category. The House text has no country limitation; the version that does is the Senate bill, which has not moved
  • Reported third-country arrangements are not illegal under current rules. Out of scope, not evasion
  • Japan is the same: renting compute is in principle not licensable, because goods are movable property
  • But SaaS provision of controlled programs, access to customer technology, and technical assistance are all caught. The gap is compute itself
  • Japan's fifteen critical infrastructure sectors do not include cloud
  • The Japanese government is not ignoring the issue; it is working a different angle, data protection, and deliberately pacing itself
  • Neither jurisdiction has text saying "not covered." Recognize the negative argument for what it is and confirm your case

An area the rules have not caught up with is, by definition, an area where the rules can change quickly. The stay on the Affiliates Rule lifts in November 2026. Rather than designing a business around a gap, it is worth knowing what happens to you when the gap closes.


Footnotes

  1. 15 CFR §734.13 "Export". eCFR, as of August 18, 2026. https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-734/section-734.13

  2. Bureau of Industry and Security, Advisory Opinion: Application of the EAR to Grid and Cloud Computing Services, January 13, 2009. https://www.bis.gov/media/documents/application-ear-grid-cloud-computing-services.pdf

  3. 88 FR 73458 (October 25, 2023), "Implementation of Additional Export Controls: Certain Advanced Computing Items," Topic 46. https://www.federalregister.gov/documents/2023/10/25/2023-23055/

  4. U.S. House Select Committee on the Chinese Communist Party, Buy What It Can, Steal What It Must: China's Campaign to Acquire Frontier AI Capabilities, April 16, 2026, p.4. https://www.govinfo.gov/content/pkg/GOVPUB-Y4_2_C44-PURL-gpo255259/pdf/GOVPUB-Y4_2_C44-PURL-gpo255259.pdf

  5. H.R. 2683, 119th Congress, Engrossed in House (passed January 12, 2026). https://www.govinfo.gov/content/pkg/BILLS-119hr2683eh/html/BILLS-119hr2683eh.htm

  6. Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949). e-Gov. https://laws.e-gov.go.jp/law/324AC0000000228

  7. METI, circular on transactions requiring permission under FEFTA Article 25(1) and Cabinet Order Article 17(2) (services circular), as last amended by Export Notice 2025 No. 27. https://www.meti.go.jp/policy/anpo/law_document/tutatu/t10kaisei/ekimu_tutatu.pdf

  8. Industrial Structure Council, Subcommittee on Security Trade Control, Interim Report, April 24, 2024. https://www.meti.go.jp/shingikai/sankoshin/tsusho_boeki/anzen_hosho/pdf/20240424_1.pdf

  9. Expert Panel on Economic Security Legislation, Recommendations for Further Promotion of Economic Security, January 30, 2026. https://www.cas.go.jp/jp/seisaku/keizai_anzen_hosyohousei/r8_dai15/teigen.pdf

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles