Most export control conversations focus on where goods physically cross a border. Two of the EAR's more consequential rules don't require a border crossing at all: the deemed export rule can be triggered by a conversation in a conference room, and the Military End-User rule has an entire enforcement track that no screening list will ever catch.
1. What "Deemed Export" Actually Means
Under 15 CFR §734.13, releasing technology or source code subject to the EAR to a foreign national is "deemed" to be an export to that person's country — even if the release happens entirely within the United States and the person never leaves the building. Common triggers include:
- A foreign national engineer or researcher joining a U.S. R&D team with system access to controlled technical data.
- A visiting scholar, contractor, or vendor support technician who can view controlled source code or schematics during a site visit.
- Cloud or IT infrastructure support staff outside the U.S. who can access controlled technology hosted on U.S. systems (a "deemed reexport," governed by the same underlying test).
If the technology in question would require a license to physically export to that person's country, releasing it to them domestically requires the same license. The trigger is the release of controlled information, not a shipment.
2. Whose Nationality Actually Matters
For employees or contractors holding citizenship or permanent residency in more than one country, BIS's current approach looks at the person's most recent citizenship or permanent residency, rather than every country of which they hold nationality. This matters operationally: export control questionnaires used during hiring and contractor onboarding need to ask about current and most recent status specifically, not simply "what citizenships do you hold," to produce an answer that actually maps to the regulation. Employers relying on outdated intake forms may be collecting the wrong data point entirely.
3. The Military End-User Rule Has Two Separate Tracks
Section 744.21 restricts exports, reexports, and transfers of specified items to military end uses and military end users in a defined set of countries. Compliance teams frequently treat this as a single list-matching problem. It isn't — there are two independent mechanisms:
| Track | How It Works | Can You Screen For It? |
|---|---|---|
| Military End-User (MEU) List | BIS maintains a named list of specific companies (Supplement No. 4 to Part 744) determined to be military end users. Any listed item shipped to a named entity requires a license, full stop. | Yes — this is a standard list-match, the same as any other restricted party screening. |
| General military end-use / end-user restriction (§744.21(a)-(b)) | Requires a license for specified items when the exporter knows the item is intended for a military end use or military end user in a covered country — regardless of whether the counterparty appears on any list. | No — this depends on facts about the transaction (stated end-use, industry, red flags), not the counterparty's identity. |
A counterparty that has never been named to any list can still trigger a license requirement under the second track if the facts of the transaction put the exporter on notice — or should have. "We ran restricted party screening and got no hits" is a true statement that, by itself, says nothing about whether the knowledge-based track applies. For the analogous issue on the sanctions side of the house, see our breakdown of denied party screening vs. restricted party screening vs. sanctions screening — the same "a clean list-check isn't the whole compliance picture" pattern shows up in both.
Screening tells you who a counterparty is. It cannot tell you what they intend to do with what you're about to send them — that's a due-diligence question, not a database lookup.
4. Red Flags the Knowledge-Based Test Actually Looks For
Since the general military end-use restriction turns on what an exporter knew or had reason to know, BIS guidance and enforcement history point to recurring red flags:
- A buyer requests packaging or labeling that obscures the true end-use or end-user.
- The stated end-use is vague, inconsistent with the item's typical application, or the customer is reluctant to provide an end-use statement.
- Shipping routes pass through freight forwarders or intermediaries in jurisdictions with known diversion risk before reaching the stated destination — the same pattern covered in our transshipment and circumvention corridor framework.
- The order size or configuration is inconsistent with the buyer's stated commercial application (e.g., commercial-grade quantities of a dual-use component ordered by an entity with no evident commercial production capacity).
None of these are things a name-matching engine detects. They require the transaction itself — order details, shipping instructions, counterparty behavior — to be reviewed against a red-flag checklist, ideally by someone trained to recognize them.
5. A Practical Compliance Checklist
- Maintain a Technology Control Plan (TCP) for any facility or team handling EAR-controlled technology, specifying who can access what, and screening new hires/contractors for deemed export exposure before granting system or lab access — not after.
- Re-run deemed export screening on status changes. A visa status change, new permanent residency, or a change in project assignment can change the applicable license determination for someone already on staff.
- Screen every counterparty against the MEU List as a standard part of restricted party screening — this catches the named-entity track automatically.
- Separately train sales and export teams on military end-use red flags for the knowledge-based track, since no list-screening product will surface it. Document the end-use review for every order above a defined risk threshold, not just the ones that trip a screening alert.
- Keep license determination records. If a compliance question ever arises, the ability to show what was known at the time of the transaction — and what due diligence was performed — is the actual defense, not a clean screening log alone.
Frequently Asked Questions
What is a deemed export? Under 15 CFR 734.13, releasing EAR-controlled technology or source code to a foreign national — including your own employee or contractor — inside the United States is "deemed" to be an export to that person's country. If a license would be required to physically export that technology to that country, one is required to release it to that person domestically, regardless of where the release happens.
Is the Military End-User List the same as the military end-use rule? No, and this is the most commonly missed distinction. The Military End-User (MEU) List (Supplement No. 4 to Part 744) is a static list of named companies — screening against it is a straightforward list-match. The broader military end-use and end-user rule in 744.21(a)-(b) applies based on what the exporter knows or has reason to know about the transaction, independent of whether the counterparty appears on any list.
Does restricted party screening catch military end-use risk? Only partially. Screening against the MEU List catches the named-entity track. It does not catch the knowledge-based track, which depends on facts about the transaction — unusual shipping routes, end-use statements, the buyer's stated industry — that a name-matching tool has no way to evaluate.
§734.13 — Export
Electronic Code of Federal Regulations (eCFR), Export Administration Regulations • 2026
§744.21 — Restrictions on Certain Military End Uses and Military End Users
Electronic Code of Federal Regulations (eCFR), Export Administration Regulations • 2026
Lists of Parties of Concern
U.S. Bureau of Industry and Security (BIS) • 2026
Frequently asked questions
What is a deemed export?
Under 15 CFR 734.13, releasing EAR-controlled technology or source code to a foreign national — including your own employee or contractor — inside the United States is 'deemed' to be an export to that person's country. If a license would be required to physically export that technology to that country, one is required to release it to that person domestically, regardless of where the release happens.
Is the Military End-User List the same as the military end-use rule?
No, and this is the most commonly missed distinction. The Military End-User (MEU) List (Supplement No. 4 to Part 744) is a static list of named companies — screening against it is a straightforward list-match. The broader military end-use and end-user rule in 744.21(a)-(b) applies based on what the exporter knows or has reason to know about the transaction, independent of whether the counterparty appears on any list.
Does restricted party screening catch military end-use risk?
Only partially. Screening against the MEU List catches the named-entity track. It does not catch the knowledge-based track, which depends on facts about the transaction — unusual shipping routes, end-use statements, the buyer's stated industry — that a name-matching tool has no way to evaluate.
In-depth intelligence briefings on global trade restrictions, dual-use technology controls, and maritime sanctions enforcement.