# Technical-data recipient and access map

A fictional engineering team maps a proposed AI service before considering a separate record that may be controlled. The controlled record is not included.

Synthetic system and recipient roles only. No controlled engineering content, real export classification, licence or authorisation is represented.

Source: https://aona.ai/resources/guides/itar-technical-data-ai-tools/
Sources checked: 2026-09-21

## Follow the content and access

### Source

Classification and intended purpose

### Processing

Application and model recipients

### Additional access

Support, logs, connections and intermediaries

### Review

Locations, plaintext, keys and legal authority

| Map point | Fictional proposed route | Question before a real decision |
| --- | --- | --- |
| Source record | Engineering document with classification unresolved. | What is the actual jurisdiction/classification and supporting determination? |
| Employee device | Input assembled on a managed device in the United States. | Which local users and services can access the material? |
| Application operator | External AI interface sends content for model processing. | Who is the legal recipient and what content can it read? |
| Model and hosting service | Processing location and authorised personnel are not established. | Where is processing, and who can obtain plaintext or access information? |
| Support, logs and connected tools | Potential additional recipients and retained copies. | What onward access exists, in which roles and locations, under which authority? |
| Encryption and keys | Transport encryption is proposed; end-to-end conditions are unverified. | Do actual key/recipient arrangements satisfy any relied-upon exception? |
| Review outcome | Material facts remain unresolved in this exercise. | Do not treat the map as permission to transmit controlled material. |

## Review checklist

- [ ] Establish data classification
  Record the export-control determination and supporting basis for the actual information.
- [ ] Trace readable access and keys
  Include model processing, support, logs, connections and intermediaries, not just hosting country.
- [ ] Resolve the authorisation or exception
  Have the accountable export-control owner apply current requirements to the exact recipients and use.

## Included example files

- itar-ai-recipient-access-map.md
- itar-ai-recipient-access-map.csv

## Source references

- 22 CFR 120.33: Technical data: https://www.law.cornell.edu/cfr/text/22/120.33 (2026-09-21)
- 22 CFR 120.50: Export: https://www.law.cornell.edu/cfr/text/22/120.50 (2026-09-21)
- 22 CFR 120.56: Release: https://www.law.cornell.edu/cfr/text/22/120.56 (2026-09-21)
- 22 CFR 120.54: Activities that are not exports: https://www.law.cornell.edu/cfr/text/22/120.54 (2026-09-21)
- State Department: Aircraft survivability equipment amendment: https://www.govinfo.gov/content/pkg/FR-2026-08-28/html/2026-17660.htm (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
