Skip to content
Saturday, August 29, 2026
USA POST 21BUSINESS LAW · CORPORATE GOVERNANCE
S&P 500−0.35%FTSE 100−0.17%Euro/Dollar+0.22%Brent Crude+1.25%10-Year US+1.40%
USA POST 21BUSINESS LAW · CORPORATE GOVERNANCE
Home / Trade
Trade

Export Controls Under the EAR: Licenses, De Minimis Rules and Entity List Risks

The Export Administration Regulations govern dual-use technology exports — and reach foreign-made goods containing more than de minimis U.S. content.

JB
Julia Brooks · March 18, 2026 · 5 min read
ShareXFacebookLinkedInTelegramEmail
Compliance officer screening shipments at a semiconductor facility

The Export Administration Regulations (EAR) — administered by the Commerce Department's Bureau of Industry and Security (BIS) — control exports of dual-use items: commercial technology, software and equipment with military or proliferation applications. The regime reaches more than shipments from U.S. docks: re-exports of foreign-made items containing more than de minimis U.S.-controlled content, exports of software source code and technology to foreign nationals (a deemed export), and transactions with parties on restricted lists including the Entity List. Violations carry civil penalties up to roughly $364,000 per violation or twice the transaction value, and criminal exposure to 20 years — with 2022-2025 enforcement against Russian, Chinese and Iranian procurement networks running in the billions of dollars.

USA Post publishes information about export-control law, not legal advice. Companies should confirm classifications and licensing with counsel and BIS guidance.

How do you know if your product is controlled?

Three steps. First, determine whether the item is subject to the EAR at all — most commercial goods are, via the Commerce Control List (CCL) categories 0-9; purely EAR99 items are the residual catch-all, low-controlled but still subject to end-user and end-use restrictions. Second, classify: an ECCN (Export Control Classification Number) assigns the item to a control entry with its reasons for control — national security, missile technology, nuclear, chemical-biological, or crime control. Classification is self-performed or via a formal BIS commodity classification (CCATS). Third, check the destination and parties: a license requirement arises from the matrix of ECCN reasons-for-control and destination, plus the lists — Entity List (license requirements for named entities, frequently with a presumption of denial), Denied Persons List, Unverified List, and Military End User rules for China, Russia, Venezuela and others.

What is the de minimis rule?

The provision that makes EAR global. Foreign-made items incorporating more than a threshold of controlled U.S.-origin content are subject to the EAR when re-exported: 25 percent for most destinations, 10 percent for Cuba, Iran, North Korea, Sudan and Syria (and 0 percent for certain Huawei-affiliated entities under the foreign direct product expansions). The foreign direct product rules — expanded dramatically in 2020-2022 for Huawei and for Russia — subject foreign-produced items built from U.S. technology or software or produced with U.S. equipment, even with no U.S. content in the final good. The result: a European chip-maker using U.S. EDA software may need a BIS license to ship to a listed Chinese customer. Supply chains now map their U.S. content and U.S.-tool exposure precisely because their customers demand it.

What are deemed exports?

Releasing controlled technology to a foreign person inside the United States is an export to that person's country — the deemed-export rule. Universities, labs and employers obtain licenses (or rely on the largely removed license exception for employees of U.S. companies) before giving nationals of controlled countries access to controlled technical data. The practical footprint: access-control segregation of controlled repositories, technology-control plans, and visa-linked reviews. Enforcement has concentrated on willful cases, but civil exposure from sloppy access controls is real and self-disclosed frequently.

How do enforcement and penalties actually work?

Through BIS administrative cases, DOJ prosecutions, and interagency task forces. The 2022-2025 Russia sanctions era made export control a front-line instrument: sweeping Entity List additions of Russian, Chinese and third-country procurement entities; the first-ever BIS temporary denial orders against shipping lines; and consolidated settlements — such as the 2023-2024 resolutions with major electronics distributors — totaling hundreds of millions. Voluntary self-disclosure remains the central mitigating act, with penalty schedules crediting disclosure and remediation heavily. The enforcement triad BIS repeats: know your customer (red-flag diligence), classify your product, and screen every transaction against the lists — consolidated screening through the Sanctions List Service API is now standard practice.

What should a compliance program contain?

  1. An item-level jurisdiction and classification inventory — ECCN or EAR99 — maintained with engineering, refreshed on product change.
  2. Automated restricted-party screening at order entry and again at shipment, with escalation rules for hits.
  3. De minimis and FDP analysis for foreign-manufactured products and foreign subsidiaries, documented in the file.
  4. Technology-control procedures: physical and digital segregation of controlled technical data, deemed-export licensing where needed.
  5. Recordkeeping for five years, training tied to roles, and an escalation channel for red-flag orders — distributors with end-user opacity are the standing risk.

Where is the regime heading?

Toward wider lists and deeper extraterritoriality. The 2022 October 7 China semiconductor controls introduced whole-of-technology restrictions — advanced computing chips, semiconductor manufacturing equipment, and U.S.-person support controls — tightened repeatedly through 2023-2025 as capabilities shifted; AI diffusion rules proposed in 2025 extended licensing frameworks to model weights and computing capacity. Allies adopted parallel regimes through coordinated plurilateral actions, making the U.S. rules a de facto global standard. For exporters, the operational answer is a living classification-and-screening infrastructure: the rules have moved too fast for annual policy reviews, and the enforcement posture rewards companies that can show their controls moved with them.

Frequently Asked Questions

What does the EAR regulate?
Exports and re-exports of dual-use items — commercial technology, software and equipment with military or proliferation uses — administered by the Commerce Department's Bureau of Industry and Security.
When does a foreign-made product need a U.S. export license?
When it contains more than de minimis controlled U.S. content (usually 25 percent), or when it is a foreign direct product of U.S. technology, software or equipment under the expanded FDP rules.
What is a deemed export?
The release of controlled technology to a foreign person inside the United States, treated as an export to that person's country and potentially requiring a license.
What are the penalties for EAR violations?
Civil penalties up to roughly $364,000 per violation or twice the transaction value, and criminal penalties up to 20 years' imprisonment for willful violations; voluntary self-disclosure substantially mitigates.