Export controls on dual-use items in the EU are no longer a matter reserved for logistics or traditional industry. Today, they affect research centres and universities on a cross-cutting basis, as well as private companies, public entities, integrators, cloud providers, consultancies and developers, because the “exportable vector” is no longer limited to equipment: it includes software, technology and technical capability.
The most common blind spot is not physical shipments, which still exist, but intangible transfers: repositories, remote access, collaborative clouds, technical deliverables, advanced support, specialised training and, increasingly, the making available of software as a product or as a service (SaaS, APIs, managed platforms). In this context, AI is one of the most sensitive fronts, due to its strategic value, ease of digital distribution and potential dual-use applications.
1) Why this is not (only) about trade: the framework regulates “intangible” acts
Regulation (EU) 2021/821 is not limited to “customs exports”. Its definition of export includes the transmission of software or technology by electronic means to a destination outside the EU customs territory, as well as the making available in electronic form of software or technology to persons outside that territory.
For this reason, the analysis is triggered both in international collaborative projects, which are very common in R&D, and in digital business models. What matters is not the physical shipment, but which technical capability is made accessible outside the EU.
2) AI: regulatory risk moves with the “enabling material”
In AI, what is “exportable” is not always the code. Often, it is the enabling material that allows capabilities to be replicated or scaled at low marginal cost. The focus shifts towards models and weights, datasets, training and inference pipelines, operational configurations, technical documentation and applicable know-how.
This is why AI deserves particular attention:
(i) it is transferred “by layers” (model, weights, dataset, API);
(ii) functions that appear neutral may be sensitive depending on the context (security, surveillance, autonomy); and
(iii) international dissemination via repositories and cloud services is, in practice, the norm.
3) SaaS and cloud: when “providing the service” may amount to an export
With digital services, it is easy to fall into a mistaken assumption: “if I do not ship anything, I am not exporting”. In export control, this is not always the case.
In general terms, a SaaS offering may constitute an “export” if it allows users outside the EU customs territory to access controlled software or technology. The reason is straightforward: Regulation (EU) 2021/821 covers electronic transmission and the making available in electronic form to persons located outside the EU. The determining factor is not the “SaaS” label, but what is made accessible outside the EU and with what level of enabling detail.
In practice, the risk increases when the service:
- provides “real” access to the technology (APIs or endpoints, advanced dashboards, repositories, operational technical documentation, downloadable artefacts); and/or
- includes advanced technical support, which may amount to technical assistance if it transfers operational know-how relating to controlled software or technology.
By contrast, where the user only consumes results, such as aggregated outputs, without access to the technical substrate or reproducible know-how, the risk profile is generally lower, although the boundary can be narrow depending on the design of the service, particularly in the areas of cyber, crypto and AI.
4) Where the “edge” usually lies: functionality and context, more than the sector
The analysis is rarely determined by the sector (academia versus industry). What is usually decisive is a combination of the level of enabling detail, maturity or applicability, and the recipient or end use. For this reason, alongside AI, cybersecurity or information security and cryptography continue to be recurring focus areas, where access to capabilities, or their technical explanation, may be equivalent to transferring technology.
5) Relevant exceptions: public domain and basic research (and the typical mistake)
Two exceptions are frequently invoked, but they must be handled with precision:
- Public domain: this may apply where information is publicly accessible without relevant restrictions on its redistribution. The critical point lies before that threshold. Publishing, or making accessible, enabling material or operational documentation may itself be the act that triggers the analysis. “Open” does not automatically mean “out of scope”, especially where reproducible artefacts such as weights, datasets or pipelines are released.
- Basic scientific research: this may fall outside the scope where it consists of theoretical or experimental work aimed at fundamental knowledge without specific practical application. Once applicable deliverables are generated, such as operational prototypes, configurations, reproducible guidelines, ready-to-use datasets or implementation know-how, the classification usually changes and must be reassessed.
Closing
Research centres and companies now share the same challenge: “exporting” may mean granting access, providing support or enabling capabilities remotely. In AI, this risk is amplified because what is valuable, and replicable, travels through digital artefacts and know-how.
Integrating export control analysis from the earliest stages, including architecture, access management, delivery models and dissemination strategy, reduces friction and helps avoid regulatory incidents that are difficult to remedy.
At Across Legal, we support companies and organisations in interpreting and applying the European export control framework and technology regulation, combining legal rigour, strategic vision and a practical approach.
↳ Discover more content in the section Insight.
↳ Do you want to stay up today about the sector related news? Follow us on LinkedIn.




