A visiting researcher joins a superconducting qubit group and, on the first morning, opens the fabrication notes on a shared drive. Nothing ships, and nobody crosses a border. Under 15 CFR 734.13, an export has taken place, and the destination is the researcher’s most recent country of citizenship or permanent residency. Section 734.15 lists three ways a release like that happens: visual or other inspection, oral or written exchange, and the application of technical knowledge abroad. A shared drive covers the first two before lunch.
For most organizations doing quantum work, this is where the exposure sits. Hardware shipments are rare, visible, and handled by people whose job is shipping. Technology releases happen in onboarding, screen shares, code repositories, lab tours, and the ten minutes after a conference talk, and in most teams nobody owns them at all. The exposure is not just in what you ship, it is in who has access. Below we set out what a deemed export is, what the current US controls reach, and which roles inside a quantum organization have to hold the process together.
What a Deemed Export Is
Under the Export Administration Regulations (EAR), an export is either a shipment out of the United States or a release of controlled technology or source code to a foreign person inside it. The second form is the deemed export, and it produces no shipping record of any kind.
“Foreign person” carries a specific meaning here. It excludes US citizens, lawful permanent residents, and protected individuals under 8 U.S.C. 1324b(a)(3), a category covering asylees and refugees. Everyone else is a foreign person for EAR purposes, including nationals of the closest allies. The license analysis then runs against the person’s most recent country of citizenship or permanent residency rather than against where they happen to be standing.
The same logic follows the technology overseas. A subsidiary in Munich that gives a Brazilian engineer access to US-origin controlled technology has made a deemed reexport to Brazil, and the US rules still apply to it. Companies with distributed engineering teams tend to find this one late.
What Changed in September 2024
Before 2024, most quantum hardware and know-how sat outside the specific control entries. Items fell into EAR99, the residual category for goods and technology subject to the regulations but not listed on any control entry, and a release to a foreign national rarely triggered a license requirement on its own. Teams could treat export compliance as a shipping function and be roughly right.
On September 6, 2024, the Bureau of Industry and Security (BIS) published an interim final rule adding entries to the Commerce Control List for quantum computing items. The new entries reach quantum computers above specified performance thresholds, the components and subsystems inside them, cryogenic and other enabling equipment, certain materials, and the software and technology for developing, producing or using any of it. Each entry carries an Export Control Classification Number (ECCN), and the ECCN sets the license requirement. BIS set the requirement for these entries to all destinations.
A worldwide license requirement changes the deemed export question from “is this person from a country of concern” to “is this person a foreign person at all.” A Canadian postdoc and a Chinese postdoc now start from the same first-order analysis, and only the available license exceptions and the licensing policy separate them.
BIS paired the rule with License Exception Implemented Export Controls (IEC), added to Part 740 and available for destinations that have adopted equivalent national controls. IEC restores much of the free movement inside the allied group, and it turns the exception’s eligible-country list into a live input to hiring and collaboration decisions rather than a footnote for the trade team.
Allies moved in the same year. The United Kingdom added quantum entries to its export control order, Canada added quantum items to its Export Control List, and the European Union updated its dual-use annex. None of it went through the Wassenaar Arrangement, the 42-state consensus body that has set these lists since 1996. Russia participates in Wassenaar, consensus on quantum entries never emerged, and a coalition of like-minded states legislated in parallel instead.
Pull the current entry text from the Commerce Control List rather than from a summary or a law firm alert, including this one. The entries have been amended since the interim rule, and thresholds are where the amendments land.
The Three Carve-Outs That Do Most of the Work
Three provisions in Part 734 remove information from the EAR entirely, and that is a stronger position than any license exception. The information is not subject to the regulations, so there’s nothing to license and nothing to report.
- Published information, section 734.7. Information already published and available to the public without restriction. Open journals, conference proceedings, published patents, and public repositories all qualify.
- Fundamental research, section 734.8. Research in science, engineering or mathematics whose results ordinarily are published and shared broadly within the community. The status depends on the publication arrangement rather than on the building, and a sponsor clause giving a funder the right to delete results before publication removes it. So does accepting a contractual restriction on which nationalities may participate.
- Educational information, section 734.9. Information released by instruction in catalog courses and associated teaching laboratories.
The Six-Element Rule for Use Technology
A fourth provision rescues more projects than the three above, and almost nobody applies it. The EAR defines technology for “use” as information covering all six of operation, installation, maintenance, repair, overhaul and refurbishing. Miss one element and it isn’t controlled use technology. An operating procedure that lets a visiting participant run a measurement, with maintenance and repair handled by staff, often sits outside the control on that basis alone. We regularly see teams lock down documentation that was never controlled in the first place, then spend a year defending an access roster they never needed.
One boundary sits outside all of this. Work performed on a defense article under a US defense contract may fall under the International Traffic in Arms Regulations (ITAR) rather than the EAR, with a different and narrower set of carve-outs. Quantum sensing and timing programs are the usual place this surfaces, and the determination belongs with counsel before the first release.
Where the Line Falls in Practice
Classification is specific to your items, and the general shape holds across organizations. Six situations, running from clearly outside the controls to clearly inside them.
- A theory result headed for arXiv. Committed to open publication at the outset, with no sponsor restriction accepted. Fundamental research, and no access analysis is needed.
- The calibration recipe for your amplifier chain. Held as a trade secret and used to produce a controlled item. This is technology for development or production, and the first-day shared-drive scenario applies to it.
- A CAD drawing on a screen during a lab tour. Visual inspection is a release under section 734.15. The tour is the export.
- A firmware repository shared with a contractor abroad. An export by transmission, and a deemed reexport as well if the contractor’s staff hold third-country nationality.
- The question period after a conference talk. The slides were cleared. The answer that goes three levels deeper than the published paper is a release, and it is the hardest one in this list to govern.
- A proposal carrying a sponsor review clause. Same experiment, same people, different jurisdictional position. The publication commitment is gone, so the fundamental research status goes with it.
Cloud and Remote Access
Giving an overseas user an account on a quantum system raises a separate analysis from handing over a design file. BIS has historically treated the provision of computing capacity differently from the release of technology or source code, and the distinction matters for anyone running a cloud-accessible machine or buying time on one. Get a written position from counsel and file it with the classification record. Teams that leave this to an informal understanding tend to discover the gap during diligence, which is the worst available moment.
The Crypto Wars Precedent
Quantum is not the first field where explaining your own work became a regulated act. Cryptography got there in the 1990s. The US government opened an investigation into Phil Zimmermann in 1993 over the international spread of Pretty Good Privacy, and closed it in January 1996 without charges. Daniel Bernstein, a graduate student at the time, sued in 1995 over the requirement that he seek government permission before publishing the source code of a cipher he had written, and Judge Marilyn Hall Patel found that source code was protected speech. Executive Order 13026 moved most encryption jurisdiction from the State Department to Commerce in November 1996, and Commerce relaxed the rules again in 2000.
The boundary that eventually held ran between published information and unpublished implementation detail, and it took most of a decade of litigation and rulemaking to draw. Quantum teams are near the start of that arc, with the same boundary and far less case law behind it. The earlier round left one lesson worth acting on. Publication intent is the strongest single lever an organization has over its own jurisdictional position, and the decision has to be made when a project is scoped rather than when the paper is submitted.
Who Owns This Inside the Organization
Compliance functions usually inherit export controls from the shipping desk, and the shipping desk is now the smallest part of the problem. Five roles decide the outcome.
- Recruiting and immigration. Form I-129, the petition for a nonimmigrant worker, carries an export control certification. The petitioning employer states whether a license is required to release controlled technology to the beneficiary of an H-1B, H-1B1 (Chile/Singapore) or L-1 petition, and commits to obtaining one before granting access. The signature is the company’s, and a classification made in haste at that point becomes a statement to a federal agency.
- The principal investigator or engineering lead. Access is granted on day one, and compliance is consulted in month three. Nearly every organization we work with has some version of that gap.
- Information technology. Repository permissions, shared drive scope, and remote access from outside the country are export controls in practice, whatever the policy document happens to call them.
- Procurement and shipping. Still real, still the traditional owner, now a minority of the risk.
- Legal and compliance. Classification, restricted party screening, licensing, and the records that prove all three happened.
BIS maintains the Entity List, a set of named parties for whom a license is required and generally denied, and it added Chinese quantum research entities to that list in November 2021 and has continued adding suppliers of upstream components since. A release to someone sponsored by, seconded from, or employed by a listed entity is caught, and so is a collaboration agreement with a listed institute. Screening the institution behind a visitor now belongs in the visitor process, alongside the badge.
The Discrimination Trap
The obvious response to all of this is to hire US citizens only. That response doesn’t remove the first problem, and it adds a second one.
Section 1324b of Title 8 prohibits discrimination on the basis of citizenship status, and the Department of Justice’s Immigrant and Employee Rights Section (IER) enforces it. Export control obligations are not a general authorization to screen by nationality, and IER’s employer guidance says so directly.
Two facts keep organizations clear of this. Lawful permanent residents, asylees and refugees are not foreign persons under the EAR at all, so excluding them is unnecessary as well as exposed. And where a license is required, applying for it is a normal cost of filling the role rather than a reason to close the role.
The sequence we teach runs in four steps. Classify the technology, identify the specific people who need access to it, determine whether an exception already covers them, and apply for licenses where one doesn’t. Nationality enters at step three, not step one.
Publishable, Partnered, Protected
Every workstream sorts into one of three categories, and the sorting is a decision the organization makes rather than a fact it discovers.
Publishable. Committed to open publication at project start, with no funder restriction accepted on publication or on participation. The category needs no access roster and no license analysis. It is the cheapest work to run, and it should be as large a share of the portfolio as the science allows.
Partnered. Shared under written terms with named organizations in named countries. Classification recorded before the first release, export authority identified in advance, and the agreement drafted to survive a rule change. One clause is worth adding by default: each party keeps usable rights in jointly developed intellectual property if the collaboration has to stop for legal reasons.
Protected. Access by named individual rather than by group or department. Kept off general shared drives, out of the standard onboarding bundle, and off the lab tour route.
The failure we see most often is drift. A project starts publishable, a commercial partner arrives, the classification changes, and the access list stays where it was in year one. Reclassification without a matching access review is the standard finding in a first export audit.
What a Technology Control Plan Contains
A Technology Control Plan is the written record showing how an organization identifies controlled technology, classifies it, and restricts access to it. BIS expects one to exist, asks for it during an investigation, and routinely makes it a condition of a deemed export license. Small teams assume the document belongs to large companies. It runs to a few pages, and it’s the first thing an investigator asks for. Eight elements cover it.
- A classification record for each item, technology and software, giving the determination, the basis for it, the person who made it, and the date.
- A named accountable owner, with a deputy.
- An access roster keyed to citizenship or permanent residency, reviewed on a fixed cycle.
- Physical and information technology controls proportionate to the classification.
- A visitor and tour procedure, including restricted party screening of the sponsoring institution.
- A publication decision log recording the intent set at project start.
- Records retained for five years, per 15 CFR Part 762.
- Training records for everyone holding access.
The First 90 Days
- Classify. Take the ten technologies your team holds that are closest to the new control entries and produce a written determination for each. Most organizations find that three or four items drive the entire picture.
- Map the people. List everyone with access to those items, with most recent citizenship or permanent residency. Contractors, interns and cloud administrators go on the same list.
- Fix the day-one problem. Move export screening ahead of account provisioning in the onboarding sequence. This single change removes the most common violation.
- Reconcile the immigration filings. Check the export certifications on filed I-129 petitions against the classifications from step one, and correct any that no longer hold.
- Write the plan. Short and current beats long and stale.
Building the Capability Internally
Export judgment in quantum sits between two skill sets that rarely meet in one person. Trade compliance professionals know Part 734 cold and can’t tell a controlled cryogenic amplifier from a catalog part. Physicists can tell the difference and haven’t read Part 734. Organizations that handle this well grow people who hold both halves, and that is a training problem well before it is a hiring problem.
Quantum Academy’s certification programs build the technical foundation these judgments rest on, from hardware modalities and cryogenic infrastructure through to the policy and sovereignty questions that sit behind the control lists. The current catalog is at quantumacademy.com/. For the wider geopolitics of how these regimes formed across jurisdictions, PostQuantum.com’s analysis of quantum export controls goes considerably further. And for the workforce side of this, including the research security and trade compliance roles now appearing in quantum job descriptions, QuantumCareers.com tracks where the demand is going.