Framework for Artificial Intelligence Diffusion

United States

RAI-US-NA-EARAICN-2023
Effective: October 7, 2022
In Force (Amended)(In Force (Amended))
RegulationRisk ManagementInternational Alignment
Export PDF

The U.S. Export Administration Regulations (EAR) on AI and advanced computing controls safeguard national security by restricting the proliferation of sensitive technologies.

Overview

The U.S. Export Administration Regulations (EAR) on AI and advanced computing controls represent a critical component of the United States' strategy to manage the global diffusion of sensitive dual-use technologies. These regulations, primarily administered by the Bureau of Industry and Security (BIS) within the Department of Commerce, aim to protect national security and foreign policy interests by preventing adversaries from acquiring technologies that could support military modernization, weapons of mass destruction (WMD) programs, or other malign activities. The framework has evolved significantly, with initial comprehensive controls on advanced computing integrated circuits (ICs) and semiconductor manufacturing equipment (SME) being introduced in October 2022. These foundational rules established licensing requirements for the export and reexport of specific high-performance ICs and related manufacturing items to certain destinations and entities of concern, particularly targeting the People's Republic of China (PRC).

A major expansion and refinement of these controls occurred with the publication of the 'Framework for Artificial Intelligence Diffusion' interim final rule (IFR), which became effective on January 13, 2025. This IFR broadened the scope to include a worldwide license requirement for advanced computing ICs and, for the first time, introduced controls on the model weights of certain advanced closed-weight dual-use AI models. However, a pivotal development occurred on May 13, 2025, when BIS announced a pause in the enforcement posture regarding the AI model weights controls under the AI Diffusion Rule, indicating a planned formal rescission and replacement rule. Despite this specific pause concerning AI model weights, the overarching controls on advanced computing hardware and related technologies, including the expanded Foreign Direct Product (FDP) rules and end-use/end-user restrictions, remain actively in force, requiring continuous vigilance and compliance from affected industries globally.

Definitions

The Export Administration Regulations (EAR) define several key terms crucial for understanding the scope and application of AI and advanced computing controls. 'Advanced Computing Integrated Circuits (ICs)' refer to high-performance semiconductors, including advanced logic ICs and high-bandwidth memory (HBM), designed for demanding computational tasks such as training sophisticated AI models and powering supercomputers. These are typically identified by specific Export Control Classification Numbers (ECCNs) on the Commerce Control List (CCL), such as 3A090.a and 4A090.a, which delineate their technical parameters and control reasons. The controls are often triggered by performance metrics like 'Total Processing Performance' (TPP) or 'bidirectional transfer rate' for memory.

'AI Model Weights,' as defined in the 'Framework for Artificial Intelligence Diffusion' under ECCN 4E091, referred to the numerical parameters of advanced closed-weight dual-use artificial intelligence models trained using 10^26 or more computational operations. While this specific control on model weights is currently under a non-enforcement posture as of May 13, 2025, the definition highlights BIS's intent to regulate the most powerful AI capabilities. An 'Export Control Classification Number (ECCN)' is a five-character alphanumeric code used to classify items on the CCL, indicating whether an item is subject to control and for what reasons (e.g., national security, missile technology). The 'Foreign Direct Product (FDP) Rule' is a critical extraterritorial provision that extends EAR jurisdiction to certain foreign-produced items that are the 'direct product' of specified U.S. technology or software, or produced by plants that are themselves the direct product of specified U.S. technology or software, when destined for certain prohibited end-uses or end-users. Other important terms include 'Supercomputer,' defined by aggregate processing unit performance, and 'U.S. Person Activities,' which can trigger controls even for activities outside the United States.

Governance and Institutional Framework

The governance and institutional framework for U.S. export controls on AI and advanced computing are primarily centered within the U.S. Department of Commerce, specifically through its Bureau of Industry and Security (BIS). BIS is the lead agency responsible for developing, implementing, and enforcing the Export Administration Regulations (EAR), which govern the export, reexport, and in-country transfer of most commercial and dual-use items. BIS derives its authority from the Export Control Reform Act (ECRA) of 2018, which provides the legal basis for its principal authorities to control items for national security, foreign policy, and short supply reasons. The agency operates with a mandate to prevent sensitive technologies from falling into the hands of adversaries while simultaneously fostering U.S. technological leadership and facilitating legitimate trade with allies.

BIS works in close coordination with various interagency partners within the U.S. government, including the Departments of Defense, State, Energy, and the intelligence community, to formulate and update export control policies. This collaborative approach ensures that controls are strategically aligned with broader national security objectives and foreign policy priorities. The process for developing new regulations, such as the 'Framework for Artificial Intelligence Diffusion,' typically involves extensive analysis, public comment periods, and iterative adjustments to respond to rapid technological advancements and evolving geopolitical landscapes. BIS also plays a crucial role in outreach and guidance, providing resources like 'Know Your Customer' guidance and red flag indicators to assist exporters in complying with the complex and frequently updated regulatory requirements.

Key Focus Areas

The U.S. Export Administration Regulations (EAR) on AI and advanced computing primarily focus on several critical areas to achieve their national security objectives. A central focus is 'Advanced Computing Integrated Circuits (ICs),' including high-performance logic ICs and high-bandwidth memory (HBM), which are essential for training and deploying advanced AI models and supercomputing applications. These items are subject to stringent global licensing requirements, with controls often tied to specific technical performance parameters. The regulations also target 'Semiconductor Manufacturing Equipment (SME)' and related software and technology, recognizing that controlling the tools necessary to produce advanced chips is as vital as controlling the chips themselves.

Another significant focus, albeit with a recent change in enforcement posture, has been 'AI Model Weights.' The 'Framework for Artificial Intelligence Diffusion' IFR, effective January 13, 2025, initially imposed a new worldwide license requirement for the model weights of certain advanced closed-weight dual-use AI models trained on a vast number of computational operations (10^26 or more). However, as of May 13, 2025, BIS announced a pause in the enforcement of these specific model weight controls, with plans for a formal rescission and replacement rule. Despite this, the intent to manage the diffusion of advanced AI capabilities remains a strategic priority. Furthermore, the expansion of 'Foreign Direct Product (FDP) Rules' is a key element, extending U.S. jurisdiction to foreign-produced items that are the direct product of specified U.S. technology or software, thereby preventing circumvention of controls. Finally, robust 'End-Use and End-User Controls' are paramount, requiring licenses for items destined for military end-uses, military end-users, or WMD programs, regardless of the item's classification.

Implementation Framework

The implementation framework for U.S. export controls on AI and advanced computing is multi-layered, relying on a combination of licensing requirements, license exceptions, and due diligence obligations. At its core, the regulations establish 'worldwide license requirements' for the export, reexport, or in-country transfer of specified advanced computing ICs and related items, particularly those classified under ECCNs 3A090.a, 4A090.a, and corresponding '.z' items. This global requirement signifies a shift from previous destination-specific controls, reflecting the pervasive national security concerns associated with these technologies. Applications for such licenses are reviewed based on factors including the sensitivity of the destination, the quantity of compute power, the performance of the AI model, and the security measures agreed to by the recipient.

To balance control with legitimate commercial and research activities, BIS has also introduced and revised various 'license exceptions.' These include the new License Exception Artificial Intelligence Authorization (AIA) for exports to certain U.S. allies and partners, and the License Exception Low Processing Performance (LPP) for items below specific performance thresholds. The framework also includes updates to the 'Data Center Validated End-User (VEU) authorization,' allowing companies headquartered in the U.S. and close allies to obtain universal authorizations for building and operating data centers, subject to specific restrictions and security obligations. Crucially, the regulations place a significant emphasis on 'due diligence,' requiring exporters and other parties to conduct rigorous 'Know Your Customer' (KYC) procedures and implement robust screening to prevent unauthorized remote access or diversion to prohibited end-uses or end-users. Compliance with these measures is essential, and the requirements extend to infrastructure-as-a-service (IaaS) providers when training advanced AI models.

Monitoring and Evaluation

Monitoring and evaluation are integral to the effectiveness and adaptability of the U.S. Export Administration Regulations (EAR) concerning AI and advanced computing. Given the rapid pace of technological innovation in these sectors, the Bureau of Industry and Security (BIS) adopts an iterative approach to rulemaking, continuously assessing the impact of existing controls and identifying areas for refinement or expansion. This ongoing evaluation process involves close collaboration with interagency partners, industry stakeholders, and academic experts to gather intelligence on technological advancements, market trends, and potential national security risks. The agency regularly publishes interim final rules (IFRs) and invites public comments, providing a formal mechanism for external input and ensuring that the regulations remain as targeted and effective as possible while minimizing unintended burdens on legitimate trade.

BIS's monitoring efforts extend to tracking compliance with licensing requirements, investigating potential violations, and enforcing penalties for non-compliance. The agency utilizes various tools, including pre-license checks, post-shipment verifications, and intelligence analysis, to ensure that controlled items are used in accordance with stated end-uses and by authorized end-users. The framework also incorporates mechanisms for updating lists of restricted entities (e.g., the Entity List, Military End-User List) and country groups, which are critical for dynamically adjusting the scope of controls in response to evolving threat landscapes. Furthermore, the periodic issuance of frequently asked questions (FAQs) and guidance documents helps clarify complex aspects of the regulations, supporting industry compliance and providing insights into BIS's interpretative positions. This continuous cycle of monitoring, evaluation, and adaptation underscores the dynamic nature of export controls in the fast-changing domains of AI and advanced computing.

Penalties, Liability, and Appeals

Non-compliance with the U.S. Export Administration Regulations (EAR) on AI and advanced computing controls can result in substantial penalties, encompassing both criminal and administrative sanctions. The Bureau of Industry and Security (BIS) is empowered to impose severe administrative penalties, which can include significant monetary fines per violation, denial of export privileges (prohibiting participation in any transaction subject to the EAR), and seizure of items. For serious violations, these administrative actions can effectively prevent a company or individual from engaging in international trade. The specific penalties are determined based on the nature and severity of the violation, the degree of intent, and the cooperation of the party involved.

In addition to administrative penalties, individuals and companies found to have knowingly or willfully violated the EAR may face criminal prosecution, leading to even more severe consequences. Criminal penalties can include substantial prison sentences for individuals and multi-million dollar fines for corporations. The U.S. government views violations of export control laws, particularly those involving sensitive technologies like AI and advanced computing, as serious threats to national security. Parties subject to BIS enforcement actions have rights to due process, including the opportunity to respond to allegations, present evidence, and, in certain circumstances, appeal decisions through established administrative procedures. This includes the right to request an administrative hearing and to appeal adverse decisions to higher authorities within the Department of Commerce. The emphasis on rigorous due diligence and 'Know Your Customer' guidance highlights the expectation that companies actively prevent violations, and failure to do so can contribute to findings of liability.

Relationship to Other Instruments

The U.S. Export Administration Regulations (EAR) for AI and advanced computing controls operate within a broader ecosystem of U.S. and international legal instruments governing trade and national security. Domestically, the EAR is distinct from, but complementary to, other U.S. export control regimes. For instance, the International Traffic in Arms Regulations (ITAR), administered by the Department of State's Directorate of Defense Trade Controls (DDTC), controls defense articles and services, which are inherently military in nature. While the EAR focuses on dual-use items (commercial items with potential military applications), there can be overlaps, and careful classification is required to determine the correct jurisdiction.

Furthermore, the EAR interacts with sanctions programs administered by the Department of the Treasury's Office of Foreign Assets Control (OFAC). OFAC sanctions can prohibit transactions with certain countries, entities, or individuals, regardless of the item's export control classification. This means that even if an item is not controlled under the EAR or has an applicable license exception, an OFAC sanction could still prohibit the transaction. The advanced computing and AI controls also build upon and amend various parts of the EAR itself, particularly 15 CFR Parts 732 (Steps for Using the EAR), 734 (Scope of the EAR), 740 (License Exceptions), 742 (Control Policy—CCL Based), 744 (Control Policy: End-User and End-Use Based), and 748 (Applications and Documentation). Internationally, these U.S. controls aim to align with multilateral export control regimes like the Wassenaar Arrangement, though the U.S. often implements unilateral controls that go beyond multilateral agreements to address specific national security concerns related to emerging technologies.

International Alignment

International alignment is a significant consideration in the development and implementation of U.S. export controls on AI and advanced computing. The U.S. government, through the Bureau of Industry and Security (BIS), actively engages with international partners and allies to coordinate efforts in restricting the proliferation of sensitive technologies. The 'Framework for Artificial Intelligence Diffusion' and related rules often employ a tiered approach, differentiating between U.S. allies and partners (referred to as Tier One Countries or those listed in Supplement No. 5 to Part 740) and other destinations. This differentiation allows for streamlined authorizations and license exceptions for exports to trusted partners, facilitating secure collaboration and shared technological development within allied nations, while maintaining strict controls for destinations of concern.

The U.S. seeks to build secure ecosystems for the responsible diffusion and use of AI and advanced computing, recognizing that a fragmented approach to export controls can be less effective. Efforts include sharing intelligence, harmonizing control lists where possible, and encouraging similar regulatory frameworks among like-minded countries. While the U.S. often implements unilateral controls to address pressing national security threats, there is a continuous dialogue to foster multilateral understanding and cooperation, particularly within forums such as the G7 and other technology-focused alliances. The goal is to create a collective front against the diversion of advanced technologies for military or malign purposes, ensuring that global technological advancements contribute to stability rather than posing risks to international security.

Implementation Timeline

MilestoneDateNotes
Initial Interim Final Rule (IFR) on Advanced Computing and Semiconductor Manufacturing Items2022-10-07Implemented controls on advanced computing ICs, computers containing such ICs, and certain semiconductor manufacturing items.
Updates and Clarifications to Advanced Computing and Semiconductor Manufacturing Item Controls2023-10-25Revised and expanded previous controls, including the SME IFR and AC/S IFR.
Foreign-Produced Direct Product Rule Additions, and Refinements to Controls for Advanced Computing and Semiconductor Manufacturing Items IFR2024-12-02Expanded FDP rules and refined controls on HBM, SME, and related software/technology. Some compliance dates were Dec 31, 2024.
"Framework for Artificial Intelligence Diffusion" IFR Effective Date2025-01-13Established worldwide license requirement for advanced computing ICs and new control on AI model weights for advanced closed-weight dual-use AI models.
"Implementation of Additional Due Diligence Measures for Advanced Computing Integrated Circuits" IFR Effective Date2025-01-16Expanded licensing requirements on foundries and packaging companies.
Compliance Required for Foundries and Packaging Companies (from Jan 16 IFR)2025-01-31Compliance date for new licensing requirements on foundries and packaging companies.
BIS Announcement of Non-Enforcement/Rescission of AI Diffusion Rule's Model Weight Controls2025-05-13BIS announced a pause in enforcement of AI model weight controls under the AI Diffusion IFR, with a planned formal rescission and replacement rule.
General Compliance Date for "Framework for Artificial Intelligence Diffusion" IFR (except security measures); Comment Period Closes2025-05-15Compliance generally required for the Jan 13 IFR; public comments due.
Delayed Compliance for Certain Security Obligations for Validated End-User (VEU) Authorizations2026-01-15Specific baseline security obligations for VEU authorizations take delayed effect.

Compliance Checklist

CheckRequired Action
Item ClassificationDetermine the correct Export Control Classification Number (ECCN) for all advanced computing ICs, AI model weights (if applicable, considering current non-enforcement), software, and technology.
Destination ScreeningVerify the country of ultimate destination against the Commerce Country Chart and relevant country groups (e.g., D:5) to identify any general prohibitions or specific license requirements.
End-User ScreeningScreen all parties to the transaction (consignees, purchasers, end-users) against the Entity List, Denied Persons List, Unverified List, and Military End-User List.
End-Use ScreeningAssess the ultimate end-use of the item to ensure it does not involve prohibited activities such as WMD programs, military end-uses in restricted countries, or unauthorized AI model training.
Foreign Direct Product (FDP) Rule AnalysisDetermine if any foreign-produced items are subject to the EAR's FDP rules due to U.S. technology/software content or production.
License Requirement DeterminationBased on classification, destination, end-user, and end-use, determine if a license is required.
License Exception ReviewIf a license is required, check if any applicable license exceptions (e.g., AIA, LPP, VEU) can be utilized, ensuring all conditions and certifications are met.
Due Diligence & KYCImplement robust 'Know Your Customer' procedures, including obtaining end-use certificates and performing enhanced due diligence, especially for high-risk transactions or IaaS providers.
RecordkeepingMaintain comprehensive records of all export-related transactions for the period required by the EAR (typically five years).
Internal Compliance Program (ICP)Establish and maintain an effective ICP to manage export control risks, including training, audits, and management commitment.

Sources and References

SourceType
Framework for Artificial Intelligence Diffusion (89 FR 4544, January 15, 2025)official
Export Controls on Semiconductor Manufacturing Items (88 FR 73424, October 25, 2023)official
Implementation of Additional Export Controls: Certain Advanced Computing Items; Supercomputer and Semiconductor End Use; Updates and Corrections (88 FR 73458, October 25, 2023)official
Implementation of Additional Export Controls: Certain Advanced Computing and Semiconductor Manufacturing Items; Supercomputer and Semiconductor End Use (87 FR 62186, October 13, 2022)official
Export Administration Regulations (EAR) Table of Contents (15 CFR Parts 730-774)government
Foreign-Produced Direct Product Rule Additions, and Refinements to Controls for Advanced Computing and Semiconductor Manufacturing Items (89 FR 96790, December 5, 2024)official
Plain English

The U.S. Export Administration Regulations (EAR) on AI and advanced computing controls aim to protect national security by restricting the global spread of sensitive technologies. This framework applies to any company or individual involved in the export, reexport, or in-country transfer of high-performance computing hardware, software, and related technology, including semiconductor manufacturers, data center operators, and even cloud service providers.

The core of these regulations, which began with initial controls in October 2022 and were significantly expanded by the "Framework for Artificial Intelligence Diffusion" effective January 13, 2025, establishes a worldwide license requirement for advanced computing integrated circuits (ICs) and related items. This means you generally need a U.S. government license to send these powerful chips anywhere, with specific exceptions for U.S. allies. A critical aspect is the Foreign Direct Product (FDP) Rule, which extends U.S. control to foreign-made items if they are the direct product of certain U.S. technology or software, preventing circumvention. Furthermore, strict end-use and end-user controls prohibit transactions with military end-users, military end-uses, or weapons of mass destruction programs, regardless of the item's classification. Companies must also perform rigorous "Know Your Customer" (KYC) due diligence, especially for high-risk transactions, to prevent unauthorized access or diversion.

A key surprise for many is the dynamic nature of these rules. While the January 2025 framework initially introduced controls on the "model weights" of certain advanced dual-use AI models, the Bureau of Industry and Security (BIS) announced on May 13, 2025, a pause in enforcing these specific AI model weight controls, with a formal rescission and replacement rule expected. However, all other hardware and related technology controls remain fully in force. Non-compliance carries severe penalties, including substantial monetary fines per violation, denial of export privileges that can halt international trade, and even criminal prosecution with prison sentences for individuals and multi-million dollar fines for corporations. The general compliance date for the AI Diffusion framework was May 15, 2025, underscoring the immediate need for vigilance.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Framework for Artificial Intelligence Diffusion. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore export, reexport, or transfer

    Applies to: Exporters of advanced computing items, software, and technology.

    Determine the correct Export Control Classification Number (ECCN) for all advanced computing ICs, AI model weights (if applicable, considering current non-enforcement), software, and technology.
  2. #2CriticalBefore export, reexport, or transfer

    Applies to: Exporters of items subject to EAR.

    Verify the country of ultimate destination against the Commerce Country Chart and relevant country groups (e.g., D:5).
  3. #3CriticalBefore export, reexport, or transfer

    Applies to: Exporters of items subject to EAR.

    Screen all parties to the transaction (consignees, purchasers, end-users) against the Entity List, Denied Persons List, Unverified List, and Military End-User List.
  4. #4CriticalBefore export, reexport, or transfer

    Applies to: Exporters of items subject to EAR.

    Assess the ultimate end-use of the item to ensure it does not involve prohibited activities such as WMD programs, military end-uses in restricted countries.
  5. #5CriticalBefore export, reexport, or transfer

    Applies to: Exporters and producers of foreign-produced items with U.S. technology or software content.

    Determine if any foreign-produced items are subject to the EAR's FDP rules due to U.S. technology/software content or production.
  6. #6CriticalBefore export, reexport, or transfer

    Applies to: Exporters of items subject to EAR.

    Based on classification, destination, end-user, and end-use, determine if a license is required.
  7. #7CriticalBefore export, reexport, or transfer

    Applies to: Exporters of advanced computing ICs (ECCNs 3A090.a, 4A090.a, and '.z' items).

    The regulations establish 'worldwide license requirements' for the export, reexport, or in-country transfer of specified advanced computing ICs.
  8. #8CriticalBefore export, reexport, or transfer

    Applies to: Exporters of items subject to EAR.

    If a license is required, check if any applicable license exceptions (e.g., AIA, LPP, VEU) can be utilized, ensuring all conditions and certifications are met.
  9. #9CriticalOngoing

    Applies to: Exporters and Infrastructure-as-a-Service (IaaS) providers.

    Crucially, the regulations place a significant emphasis on 'due diligence,' requiring exporters and other parties to conduct rigorous 'Know Your Customer' (KYC) procedures.
  10. #10CriticalJan 31, 2025

    Applies to: Foundries and packaging companies.

    Compliance Required for Foundries and Packaging Companies (from Jan 16 IFR).
  11. #11CriticalJan 15, 2026

    Applies to: Companies utilizing VEU authorizations for data centers.

    Delayed Compliance for Certain Security Obligations for Validated End-User (VEU) Authorizations.
  12. #12ImportantOngoing

    Applies to: Exporters of items subject to EAR.

    Maintain comprehensive records of all export-related transactions for the period required by the EAR (typically five years).
  13. #13ImportantOngoing

    Applies to: Organizations involved in export-controlled activities.

    Establish and maintain an effective ICP to manage export control risks, including training, audits, and management commitment.

© Regulations.AI — created on 20-May-2026 using Gemini 2.5 Flash