# Technical-data recipient and access map

Synthetic system and recipient roles only. No controlled engineering content, real export classification, licence or authorisation is represented.

A fictional engineering team maps a proposed AI service before considering a separate record that may be controlled. The controlled record is not included.

| Map point | Fictional proposed route | Question before a real decision |
| --- | --- | --- |
| Source record | Engineering document with classification unresolved. | What is the actual jurisdiction/classification and supporting determination? |
| Employee device | Input assembled on a managed device in the United States. | Which local users and services can access the material? |
| Application operator | External AI interface sends content for model processing. | Who is the legal recipient and what content can it read? |
| Model and hosting service | Processing location and authorised personnel are not established. | Where is processing, and who can obtain plaintext or access information? |
| Support, logs and connected tools | Potential additional recipients and retained copies. | What onward access exists, in which roles and locations, under which authority? |
| Encryption and keys | Transport encryption is proposed; end-to-end conditions are unverified. | Do actual key/recipient arrangements satisfy any relied-upon exception? |
| Review outcome | Material facts remain unresolved in this exercise. | Do not treat the map as permission to transmit controlled material. |

## Review steps

- Establish data classification: Record the export-control determination and supporting basis for the actual information.
- Trace readable access and keys: Include model processing, support, logs, connections and intermediaries, not just hosting country.
- Resolve the authorisation or exception: Have the accountable export-control owner apply current requirements to the exact recipients and use.

## Unrestricted teaching input

“Rewrite a generic engineering-team meeting reminder.” No technical specifications, defence design or controlled information are provided.

## Fictional assessment record

Record: TECH-EX-29, not included.
Classification: unresolved in the teaching scenario.
Potential recipients: AI interface, model service, support/logging services and a security intermediary.
US hosting: a proposed fact, not an export conclusion.
Encryption exception: not established by a TLS label.
Authorisation: none represented.

## Source-currency note

FR Doc 2026-17660, published 28 August 2026 and effective 13 October 2026, changes aircraft-related paragraphs of 120.54. It does not amend the paragraph (a)(5) encryption conditions discussed in this exercise.

## Source and scope

Guide: https://aona.ai/resources/guides/itar-technical-data-ai-tools/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- 22 CFR 120.33: Technical data: https://www.law.cornell.edu/cfr/text/22/120.33
- 22 CFR 120.50: Export: https://www.law.cornell.edu/cfr/text/22/120.50
- 22 CFR 120.56: Release: https://www.law.cornell.edu/cfr/text/22/120.56
- 22 CFR 120.54: Activities that are not exports: https://www.law.cornell.edu/cfr/text/22/120.54
- State Department: Aircraft survivability equipment amendment: https://www.govinfo.gov/content/pkg/FR-2026-08-28/html/2026-17660.htm
