AI Governance for Export-Controlled Data: An ITAR/EAR Playbook
AI governance for export-controlled data is the set of policies, technical controls, and audit mechanisms that ensure ITAR and EAR-controlled information is never processed by AI systems in ways that constitute an unauthorized export, including uploads to public LLMs, foreign-accessible cloud infrastructure, or tools with offshore support staff. The risk is not hypothetical: employees at most manufacturers have already pasted work content into consumer AI tools, and for an ITAR-registered company a single pasted drawing note can trigger disclosure obligations to DDTC. This playbook lays out a governance program that enables AI use rather than banning it.
Map the Regulatory Surface: ITAR, EAR, and the Deemed-Export Trap
Start from the legal facts. ITAR (22 CFR 120-130) controls USML defense articles and their technical data; EAR (15 CFR 730-774) controls dual-use items on the CCL, with controlled technical data under both regimes. The deemed-export doctrine treats releasing controlled data to a foreign person, anywhere, including inside the US, as an export to their home country. For AI this means three exposure paths: uploading controlled data to a service whose infrastructure or support staff include foreign persons; an AI vendor training on or retaining your prompts; and internal AI systems that surface controlled data to employees who are foreign persons without a license. The 2020 encryption carve-outs (ITAR 120.54, EAR 734.18) protect properly end-to-end encrypted transit and storage but not AI inference, which requires decryption.
Policy Layer: An AI Acceptable Use Standard With Teeth
A one-line "do not use ChatGPT" memo fails because it gives employees no compliant alternative and no clear data taxonomy. An effective standard defines data classes and maps each to permitted AI tools.
- Define classes: public, internal, CUI, EAR-controlled, ITAR technical data, each with named permitted AI tools
- Provide a sanctioned alternative: an approved internal AI so the compliant path is also the convenient one
- Require empowered-official sign-off before any new AI tool touches controlled data classes
- Train annually with concrete examples; log attestations alongside existing ITAR training records
Technical Controls: Enforce the Policy, Do Not Just Publish It
Governance holds only when the network enforces it. Practical control stack for a mid-sized manufacturer: DLP or secure web gateway rules (Zscaler, Netskope, or Microsoft Purview) blocking uploads to unapproved AI endpoints; CASB discovery to find shadow AI use; and an on-prem or GovCloud AI deployment where controlled work is actually allowed to happen.
- Block or coach on uploads to public LLM endpoints at the gateway, with logged exceptions
- Enforce document-level permissions in internal AI retrieval so foreign-person employees cannot access ITAR data without licenses
- Retain full prompt and response logs on controlled-data AI systems for audit and disclosure defense
- Review vendor contracts for data residency, US-persons support, and no-training clauses before approval
Audit, Incident Response, and Voluntary Disclosure Readiness
Assume an incident will eventually occur and build the response before it does. Define an AI data spill runbook: preserve evidence (gateway logs, the prompt, vendor retention terms), notify the empowered official, assess whether controlled data was released to foreign persons or foreign infrastructure, and evaluate voluntary disclosure to DDTC (ITAR) or BIS (EAR), where timely self-disclosure is a significant mitigating factor, DDTC penalties can otherwise reach $1 million per violation. Quarterly, audit gateway logs for shadow AI, sample internal AI prompt logs for misclassified data, and re-verify vendor commitments at renewal. Tie the whole program into your existing Technology Control Plan so AI governance is an extension of proven export compliance machinery rather than a parallel bureaucracy.
How Netray Operationalizes AI Governance
Netray gives export-controlled manufacturers the piece most governance programs lack: a compliant place for AI work to actually happen. Our on-prem AI deployments run entirely inside your facility with US-persons-only administration, document-level access enforcement wired to your existing ITAR permissions, and complete prompt audit trails formatted for empowered-official review. Alongside the technical stack, we deliver the governance artifacts: data classification mapping, AI acceptable use standard templates, Technology Control Plan addenda, and DLP blocking rule recommendations. Clients report shadow AI usage dropping by 80-90 percent within a quarter of launching the sanctioned alternative, because engineers finally have an approved tool that works on the data they actually use.
Frequently Asked Questions
Is it an ITAR violation to put technical data into ChatGPT?
Potentially, yes. Consumer AI services process data on infrastructure where foreign-person access cannot be excluded, and ITAR treats release of technical data to foreign persons as an export requiring authorization. A pasted drawing note or spec excerpt can trigger evaluation for voluntary disclosure to DDTC. Companies should block public LLM uploads for controlled data and provide an approved on-prem or US-persons-committed alternative.
Does the ITAR encryption carve-out cover AI tools?
No, not for inference. ITAR 120.54 and EAR 734.18 exclude properly end-to-end encrypted data in transit and storage from being an export, but an AI model must decrypt your prompt to process it, which breaks end-to-end protection at the provider. The carve-out can cover encrypted backup or transfer of controlled data through cloud infrastructure, but not sending that data to a cloud LLM for processing.
What should an AI acceptable use policy include for defense manufacturers?
Five elements: a data classification scheme mapping public, internal, CUI, EAR, and ITAR data to specifically permitted AI tools; a sanctioned internal AI alternative so compliance is practical; empowered-official approval gates for new AI tools; technical enforcement through DLP and gateway blocking rather than policy alone; and an incident runbook covering evidence preservation and voluntary disclosure evaluation for DDTC or BIS. Annual training with logged attestations completes the program.
Key Takeaways
- 1Map the Regulatory Surface: ITAR, EAR, and the Deemed-Export Trap: Start from the legal facts. ITAR (22 CFR 120-130) controls USML defense articles and their technical data; EAR (15 CFR 730-774) controls dual-use items on the CCL, with controlled technical data under both regimes.
- 2Policy Layer: An AI Acceptable Use Standard With Teeth: A one-line "do not use ChatGPT" memo fails because it gives employees no compliant alternative and no clear data taxonomy. An effective standard defines data classes and maps each to permitted AI tools..
- 3Technical Controls: Enforce the Policy, Do Not Just Publish It: Governance holds only when the network enforces it. Practical control stack for a mid-sized manufacturer: DLP or secure web gateway rules (Zscaler, Netskope, or Microsoft Purview) blocking uploads to unapproved AI endpoints; CASB discovery to find shadow AI use; and an on-prem or GovCloud AI deployment where controlled work is actually allowed to happen..
Put this into numbers
Free interactive tools for exactly this problem. No signup to use them.
ITAR Compliance Checklist for Manufacturers
A 32-point checklist covering DDTC registration, technical data controls, foreign person access, IT security, and recordkeeping for ITAR-regulated manufacturers.
Free ToolAI Governance Maturity Assessment
Score your AI governance across policy, inventory, risk classification, data handling, monitoring, and executive oversight, and get a banded improvement roadmap.
Free ToolSovereign AI Readiness Assessment
Score your organization across eleven dimensions of sovereign AI readiness, from data residency and model provenance to cleared personnel and air-gapped operations.
Terms used in this article
Have Netray stand up your sanctioned, on-prem AI environment and the ITAR/EAR governance package around it in one engagement.
Related Resources
ITAR-Compliant AI Tools for Manufacturing: Requirements and Options
ITAR-compliant AI tools for manufacturing: what export control rules mean for LLMs, which vendors qualify, and how to deploy AI without a deemed-export risk.
AI & AutomationCMMC-Compliant AI Deployment: What Level 2 Contractors Must Know
CMMC-compliant AI deployment explained: how Level 2 defense contractors can run AI on CUI without expanding assessment scope. Controls, enclaves, and costs.
AI & AutomationRunning LLMs in Classified and Air-Gapped Environments
Running LLMs in classified and air-gapped environments: hardware sizing, offline model updates, IL5 and IL6 hosting rules, and proven deployment patterns.