Skip to content

Regulation and governance for data buyers

Export-Controlled Technical Data in AI Training Sets: ITAR and EAR Checks for Engineering Records

Quick answer

Engineering drawings, CAD and PCB files, MRO work packages and process specifications can contain ITAR technical data or EAR-controlled technology. Copying them into a training corpus is not itself an export, but giving foreign-person staff, offshore annotators or a foreign cloud region access can be one, including a "deemed export" inside the United States [1][3]. Before ingestion, require a supplier jurisdiction and classification statement for each dataset, quarantine anything unclassified, restrict access by nationality where needed, and take the model-weights question to export counsel.

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Which engineering records carry export-control risk

The records most likely to be controlled are those that explain how to design, build, repair or modify a defense article or a listed dual-use item. The ITAR defines technical data as information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of defense articles, in forms that include blueprints, drawings, photographs, plans, instructions and documentation (22 CFR 120.33) [3]. That language maps almost one-for-one onto the document types AI teams want for document understanding and engineering agents.

Higher-risk sources, in rough order:

  • Defense-supplier drawings and models. STEP, IGES, Parasolid, native SolidWorks or NX files and their 2D drawings from tier-2 and tier-3 machine shops that build to prime contractor prints. A part may look generic and still be specially designed for a USML item.
  • Aerospace and defense MRO records. Work cards, engine shop findings, repair schemes, NDT reports and component maintenance manual excerpts. Maintenance and repair information is named in the ITAR definition [3], and commercial aircraft engine technology can sit under EAR Category 9 entries.
  • Controlled process specifications. Heat-treat, coating, composite layup and additive-manufacturing parameter sheets, where the "how" is the controlled content even when the part is not.
  • PCB and firmware packages. Gerbers, schematics and embedded source for radiation-hardened, encryption or military communications boards. ITAR technical data also covers software directly related to defense articles [3].

Lower-risk records include support tickets, purchasing data and general engineering correspondence, but these still carry attachments. A procure-to-pay dataset can hold a drawing attached to a purchase order, which is why the attachment layer of order-to-cash and procure-to-pay records deserves the same screen.

How ITAR technical data differs from EAR technology for a training set

ITAR and the EAR use different jurisdictions, different definitions and different deemed-export rules, so classify first and decide controls second. ITAR covers USML defense articles and their technical data under 22 CFR; the EAR covers dual-use and 600-series items listed on the Commerce Control List, with residual items designated EAR99 [1][3]. The current ITAR definition sits at 22 CFR 120.33 after the 2022 reorganization; older supplier paperwork that cites 120.10 refers to the pre-reorganization section.

Under the EAR, releasing controlled technology or source code to a foreign person in the United States is a deemed export to that person's most recent country of citizenship or permanent residency, governed by 734.13(b), with "release" defined in 734.15 [1][2]. The ITAR applies a comparable concept and generally looks at every country of nationality, which is stricter for dual nationals; verify the current text with counsel. For a training pipeline, "release" includes visual inspection, so an annotator viewing a drawing in a labeling tool is the event that matters, not the file transfer.

Both regimes exclude information that is already lawfully published and qualifying fundamental research, under different tests; check 15 CFR Part 734 and the ITAR public-domain definition at 22 CFR 120.34 for the current text. Do not assume a scraped or "public" drawing qualifies: the exclusion turns on how and by whom the information was made public.

Where a training pipeline creates an export

Exports in an AI program usually happen at the people and infrastructure layers, not at the moment of acquisition. Under 15 CFR 734.18, moving technology between persons in the United States who are not foreign persons is not an export. The risk arises when the corpus becomes visible to someone or somewhere else.

Common failure points:

  1. Labeling and QA vendors. Offshore or foreign-national annotators reviewing bounding boxes on drawings, or reading MRO findings to write instruction pairs.
  2. Research staff. Foreign-national ML engineers in a US lab browsing raw shards in a WebDataset or Parquet store. This is the classic deemed-export scenario [1][4].
  3. Cloud regions and replicas. Buckets replicated to a non-US region, or managed services whose support staff can access customer content.
  4. Evaluation and red-team sharing. Sending eval sets or failure cases to an external partner or model provider.
  5. Model outputs. A fine-tuned model that reproduces controlled drawings, tolerances or process parameters on request may itself release technical data to its users.

The EAR treats certain unclassified technology that is sent or stored with end-to-end encryption as not an export, subject to conditions in 734.18, and the ITAR has a parallel provision at 22 CFR 120.54. As of October 2026, check the exact conditions (encryption module standards, who holds the keys, and storage-location limits) against the current text before relying on them. Once data is decrypted for training, the carve-out no longer applies, so access controls on compute and storage have to do the work.

The supplier classification statement as an acceptance gate

Make a written jurisdiction and classification statement a condition of delivery, because the supplier usually knows the program and customer context that a buyer cannot infer from files. A drawing title block rarely says "ITAR"; the supplier's contract flow-downs, DFARS markings and customer distribution statements do. Treat silence as "unclassified," not as "EAR99."

Illustrative example: invented to show structure; it does not describe an available dataset.

FieldExample entryWhy the buyer needs it
dataset_idENG-DRW-0042Ties the statement to one delivery manifest
record_types2D PDF drawings, STEP AP242 models, inspection reportsScopes the review to actual formats
source_programsCommercial industrial pumps; no defense prime contractsMain signal for ITAR exposure
jurisdictionEARITAR, EAR, or not subject to the EAR
classificationEAR99, self-classifiedECCN or USML category, plus who classified it and how
markings_foundProprietary legend only; no ITAR, EAR or Distribution D/E markingsFlags documents needing manual review
excluded_recordsDrawings for 3 customers with defense flow-downs removed before deliveryShows the screen actually removed something
government_rightsNo DFARS 252.227 legends on delivered recordsSeparates export issues from federal data-rights clauses
reviewer_and_dateSupplier trade compliance lead, 2026-09-30Accountability and re-review trigger

Pair the statement with your own sample review. Pull a random sample of drawings and MRO records, search title blocks and notes for "ITAR," "22 CFR," "EAR," "ECCN," "Export Controlled," "Distribution Statement" and "CUI," and check part numbers against known defense platforms. A miss in the sample is a reason to reject or re-screen the lot, not to delete one file.

Decision table: what to do with each classification result

The classification result should drive concrete pipeline controls, not just a contract file. Use a table like this in your intake runbook.

Illustrative example: invented to show structure; it does not describe an available dataset.

ResultDefault handlingAccess controlEscalate when
Not subject to EAR or ITAR (published, fundamental research)Normal ingestionStandardSupplier cannot explain how the material was published
EAR99Normal ingestion with screening for sanctioned destinations and partiesStandard plus restricted-party checks on vendorsAny end use in a restricted military or WMD context
ECCN on the CCL (e.g., Category 9 "E" technology)Separate bucket; license determination per foreign-person accessNationality-based access list; US-region storageAnnotators or staff from countries requiring a license
600-series or USML / ITAR technical dataDo not ingest without counsel sign-off (plus DDTC registration review for ITAR data)US persons only; segregated computeAlways
Unknown or contradictoryQuarantineNo access beyond compliance reviewersUntil classified

Model weights and outputs trained on controlled data

Whether model weights trained on controlled technical data are themselves controlled is unsettled, so treat it as a counsel decision, not an engineering default. The question is whether weights, or outputs they can produce, constitute technical data or technology "required" for a controlled item. Commerce rules on certain advanced model weights have also shifted since 2025, so confirm the status as of October 2026 before you rely on any summary.

Practical mitigations while that question is open: keep weights trained on controlled sources in the same access tier as the sources, test the model for verbatim reproduction of drawings and process parameters, and record lineage so you can identify affected checkpoints. That lineage also supports audit-readiness evidence and retention decisions.

Contract and diligence terms to request

Export checks belong in the license and diligence pack, alongside ownership and consent checks. Ask suppliers for:

  • A per-dataset jurisdiction and classification statement, with a duty to notify if it changes.
  • A representation that controlled records were excluded, or a list of what was delivered under which classification.
  • Delivery only to named US locations and accounts, through access-controlled transfer rather than email attachments.
  • Cooperation on re-classification if your counsel disagrees.

Our due diligence checklist covers the rights and privacy side, and the data licensing and export controls insight gives background. For engineering sources specifically, see CAD and PCB design datasets, drawing-to-CAD model pairs and buyers in manufacturing.

SourceX sources operational datasets, including engineering records, from US companies on request; each dataset is rights-reviewed for ownership and consents, prepared with per-dataset diligence materials, and released only with the supplying company's approval. If you are scoping engineering or maintenance records, you can describe the data you need. Wider regulatory context is on the compliance hub and the AI data hub.

Request engineering and maintenance records for AI training

Describe the drawings, CAD files or maintenance records you need, and SourceX looks for US businesses that hold them, assesses data and licensing permissions, and agrees allowed uses in a license before anything is delivered. Nothing is contracted until a supplier agrees, and a request does not guarantee a match. Start a buyer request.

Sources

  1. U.S. Department of Commerce, Bureau of Industry and Security, "Deemed exports". https://www.bis.gov/deemed-exports
  2. U.S. Department of Commerce, Bureau of Industry and Security, "Activities That Are Not Deemed Reexports". https://www.bis.doc.gov/index.php/enforcement/oee/14-policy-guidance/deemed-exports
  3. Mondaq, "ITAR, AI-Enabled Defense Technologies, Autonomous Systems, Targeting Algorithms and the New Export Control Frontier". https://www.mondaq.com/unitedstates/new-technology/1776516/itar-ai-enabled-defense-technologies-autonomous-systems-targeting-algorithms-and-the-new-export-control-frontier
  4. CASRAI, "Deemed export and AI research". https://casrai.org/news/deemed-export-ai-research

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data