Export Controls & Compliance-as-Code
Export Controls for AI Models: BIS Weight Controls and Technical Safeguards
When AI model training and hosting triggers export controls, how model weights are classified, what technical safeguards satisfy BIS requirements, and what licenses you need
Atomic answer
AI model training and hosting triggers export controls under BIS regulations when the model's weights reach specific performance thresholds defined in the Commerce Control List. Models that exceed these thresholds are classified under ECCN 4A090 or similar categories, making their export -- including through hosted API access by foreign users -- subject to licensing requirements.
Who is this for?
This article is for AI founders, ML engineers, and CTOs building frontier models, hosted inference APIs, or fine-tuning platforms. If your model weights exceed defined computational or performance thresholds, if you serve international customers, or if you employ foreign-national engineers who access training systems -- the export control framework applies to your architecture decisions today, not at your Series B legal review. This is also relevant for investors conducting regulatory diligence on AI portfolio companies.When does AI model training or hosting trigger export controls?
Export controls for AI models activate based on the model's computational and performance characteristics, as defined in the BIS interim final rule published at 87 FR 62186 (October 2022) and subsequent updates. The key threshold is whether the model or its training cluster exceeds a defined computational threshold — historically referenced at approximately 10^23 floating-point operations for training. Models that cross this line may be classified under ECCN 4A090 or 4D090 under the Commerce Control List, depending on their nature and use.\n\nThe trigger is not limited to the final model weights. Training data sets that include controlled technical data are subject to deemed export rules when accessed by foreign nationals. Training infrastructure — including the GPU clusters and associated software — can be controlled if it is specially designed for model training above the threshold. And the trained model weights themselves are controlled when exported, including through hosted API access.\n\nThe complicating factor for AI companies is that the model that triggers controls depends on the training configuration, not just the inference-time performance. A model that was trained on a cluster exceeding the computational threshold is controlled even if the deployed model is quantized or distilled to a smaller size. This matters for companies that train large models and deploy smaller versions.\n\nThe BIS framework also includes a 'red line' for advanced AI models defined by specific performance benchmarks. Models that achieve high scores on benchmarks such as MMLU, HumanEval, or equivalent large-scale evaluations are considered advanced and may face additional restrictions regardless of their training compute threshold. Companies should monitor the Federal Register for the latest threshold values and benchmark criteria as these are subject to periodic adjustment.How are AI model weights classified under BIS regulations?
Model weights classification under BIS regulations follows the Commerce Control List structure. ECCN 4A090 covers certain advanced computing integrated circuits. ECCN 4D090 covers software related to advanced computing. Model weights can fall under 4E001 (technology for the development or production of controlled items) or under ECCN 4E090 if they meet the technical threshold for controlled AI models.\n\nThe classification framework considers both the model weights themselves and the software that generates or loads them. The weights are classified based on their ability to perform controlled functions — not on their structure or size alone. A small model that achieves high benchmark performance on specified evaluations may be controlled while a larger model that performs below the threshold may not.\n\nSelf-classification is permitted under the EAR. Companies can assess their models against the CCL criteria and assign an ECCN. The company must document the classification rationale and retain it for BIS inspection. Alternatively, the company can request a formal Commodity Classification Automated Tracking System (CCATS) determination from BIS. Processing time for CCATS requests is typically 4 to 8 weeks, though timelines vary based on BIS workload and case complexity.\n\nThe most important practical point: classification is not optional. Exporting or hosting a controlled model without classification is a violation even if the company was unaware of the control status. The BIS framework operates on strict liability for export violations.What technical safeguards satisfy BIS requirements?
BIS requirements for AI models focus on preventing unauthorized access to controlled model weights and technical data. Technical safeguards are not explicitly defined in the regulations but are evaluated based on their effectiveness at preventing export to prohibited end users and end uses.\n\nAPI-based access is the most common safeguard. When a controlled model is hosted via API, the question is whether the API provides a sufficient barrier to prevent unauthorized extraction of the model weights. An API that exposes only inference outputs without providing model parameters is generally considered a safeguard. An API that allows gradient access, fine-tuning uploads, or weight extraction presents a higher risk.\n\nHardware-rooted security including trusted execution environments (TEEs) and secure enclaves can provide additional assurance. These technologies ensure that even if an operator accesses the host system, the model weights remain encrypted and inaccessible. Hardware security modules (HSMs) can protect encryption keys for model weights at rest.\n\nDeployment architecture matters for licensing. A model deployed on US-based infrastructure with access restricted to US persons may qualify for a license exception under NAC (Notified Advanced Computing) or similar exceptions specified in the EAR. A model deployed on global cloud infrastructure with access from sanctioned countries does not qualify for exceptions and requires a license. The key architectural decision is whether the model can be logically or physically separated by user geography.\n\nBIS has signaled that robust usage monitoring, anomalous access pattern detection, and automated export control screening of API users constitute acceptable technical safeguards. Companies should consult the latest BIS guidance and Federal Register notices for current safeguard expectations as these evolve with technology.What license do you need to export AI models?
The specific license requirement depends on the model's ECCN classification, the destination country, the end user, and the end use. Most controlled AI model exports require a BIS export license under part 744 of the EAR. The license application is submitted through SNAP-R and includes a technical description of the model, its classification basis, the proposed export destinations, and the end user details.\n\nLicense processing times for AI model applications typically average 30 to 45 days for standard reviews, with expedited processing available for certain allied country destinations. The approval rate for AI model license applications to allied countries is generally high based on BIS licensing data, though specific percentages fluctuate year to year. Applications involving China or Russia are typically denied under the BIS policy of denial for certain destinations.\n\nLicense exceptions are available in specific circumstances. Exception TSR (Technology and Software Restricted) allows export of controlled technology to certain destinations for specific end uses. Exception ENC (Encryption commodities and software) may apply to AI models with encryption functionality. Companies should evaluate whether their model qualifies for any exception before filing a license application, because exceptions can reduce processing time from months to zero.\n\nThe deemed export rule applies to AI model access by foreign-national employees and contractors. If a foreign national from a controlled country accesses a controlled model during training, fine-tuning, or inference, that access constitutes a deemed export requiring a license. This is one of the most common compliance gaps for AI companies with global engineering teams.Stack & State is an editorial and ecosystem-intelligence publication. Nothing here is legal, investment, procurement, or compliance advice. Program details change; verify requirements with primary sources and qualified advisors.