Loading…
Loading…
The 2016 EAR rule had introduced two provisions:
via remote access), making it subject to EAR licence requirements.
password, or authentication credential) occurs.
An ambiguity arose: the 2016 rule's § 734.19 language referred only to "source code" when defining what a software release encompasses for access-information purposes, leaving object code (compiled, executable software) in a grey zone. Companies providing SaaS or cloud-based tools that deliver object code via a key or token were uncertain whether they faced licence obligations for foreign-national access.
This final rule corrects the ambiguity in two steps:
1. Adds a cross-reference in § 734.15 pointing to § 734.19. 2. Inserts a note in § 734.19 confirming that "release of software" in the access-information context includes both source code and object code.
The rule was effective immediately on publication (18 September 2023); no delayed implementation period was provided.
assess whether the underlying software is controlled under the CCL — if it is, providing the access credential triggers the same licence obligation as a direct export of the code.
(e.g., EDA tools, encryption software, AI frameworks with CCL-listed capabilities): a foreign customer login or API key now unambiguously constitutes an "export" for EAR purposes.
covers both source and object code delivery channels.
obligations — further rulemaking on "deemed exports" in cloud environments is anticipated.
a live question in the export-control community.