Compliance · · 6 min read

Export-controlled data and public AI: where the real risk sits

Pasting a drawing into a public chatbot can look like a harmless shortcut. In defence and aerospace, it can raise export-control questions that no one in the room noticed.

Every export-control programme is built around a simple idea: controlled technical data may only reach people and places that are authorised to receive it. Public AI tools quietly test that idea, because the data leaves your control the moment it is submitted.

This article is general information for engineers, security officers and export-control teams. It is not legal advice, and your own export-control officers and counsel remain the right people to interpret the rules for your situation.

Why the destination matters

Export-control regimes such as the US International Traffic in Arms Regulations and Export Administration Regulations, and the EU dual-use regulation, generally treat the transfer of controlled technical data as an export or release, whether it happens on paper, by email or electronically. When an engineer submits a document to a public AI service, three things are usually outside your control:

  • where the service processes and stores the data, and in which countries;
  • who can access it, including the provider’s staff and subcontractors;
  • how long it is retained, and whether it is used to improve the service.

Both the US and EU rules contain narrow provisions for data that is protected by strong encryption in transit and storage. Those provisions depend on the data not being readable outside authorised hands. A language model has to read the text to answer, so a public chatbot cannot rely on them.

The shadow AI problem

The risk rarely comes from policy decisions. It comes from engineers under time pressure. An approved internal tool is slow or weak; a public chatbot is fast and helpful. A specification, a supplier email or a non-conformance report gets pasted in, and nobody logs it. Because there is no record, an export-control team cannot assess whether a release took place, let alone report it.

Blocking public AI without offering a capable alternative does not remove the demand. It hides it.

What a defensible setup looks like

  1. Keep controlled data on models you control. Run private models inside your own cloud, data centre or air-gapped network, where your existing export-control and security measures already apply.
  2. Check before any model sees a request. A policy check should route anything that looks controlled, or that it is unsure about, to private models only.
  3. Apply access rules to AI as well. The same programme, role, nationality and licence rules that govern your document system should govern what the AI can retrieve for each user.
  4. Keep the evidence. Log every request, source, route and approval in your own infrastructure.
  5. Make the approved tool the better tool. If the internal option is as capable and fast as a public chatbot, shadow use falls away.

Where managed AI still fits

None of this means frontier models are off limits. Public regulations, published directives, tender notices and industry news carry no export-control risk, and managed models are excellent at them. The discipline lies in keeping the two apart and being able to prove it.

Discuss Hybrid AI for Your Programmes

Explore a supervised pilot on your own data, in your own infrastructure.