30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

ITAR technical data in AI: map the recipients

Classify the information and map who can access it before sending engineering material to AI. ITAR can concern transmissions abroad and releases to foreign persons within the United States. US hosting or ordinary TLS alone does not establish an exception, and a worksheet cannot authorise an export.

For Engineering security, export-control and legal teams

Aona field notesC29
Location is only one question
Who can read the data?

Trace plaintext, keys, support access and onward recipients as well as geography.

Synthetic system and recipient roles only. No controlled engineering content, real export classification, licence or authorisation is represented.

01

Establish whether the material is technical data

ITAR 22 CFR 120.33 defines technical data by its relationship to the specified defence articles and activities, including relevant design, production, operation, repair and other information. It also contains exclusions for defined categories such as general principles and basic marketing information.

Have the responsible export-control owner establish the classification and supporting basis. A filename saying confidential or public is not the legal analysis. Nor does availability somewhere on the internet automatically establish the regulation’s defined public-domain exclusion.

Source context: 22 CFR 120.33: Technical data

02

Map export and release questions separately

Section 120.50 includes transmissions outside the United States and specified releases to foreign persons in the United States, subject to its exceptions. Section 120.56 describes release circumstances. Review the actual people, entities, services and access rather than assuming the server’s country is the only relevant fact.

For AI use, identify the application operator, model provider, hosting and support arrangements, logs, connected tools and any security intermediary. Establish who can obtain the content or access information. The map is an evidence request, not an assumption that each listed recipient is foreign or unauthorised.

Source context: 22 CFR 120.50: Export · 22 CFR 120.56: Release

03

Do not equate TLS with the conditional exception

Section 120.54(a)(5) addresses certain sending, taking or storing of unclassified technical data using qualifying end-to-end encryption and other conditions. Its definition includes limits on providing decryption means to third parties. Inspect the actual plaintext and key boundaries before relying on it.

A model-processing service may need readable input; establish what that means in the proposed architecture and who is authorised to receive it. Do not infer either a universal cloud prohibition or an automatic exemption from the words encrypted, US region or private model.

Source context: 22 CFR 120.54: Activities that are not exports

04

Keep the source version and scope clear

The source page flags an amendment published at 91 FR 55460. The official rule, FR Doc 2026-17660, concerns civil aircraft incorporating survivability equipment and is effective 13 October 2026. Its changes to 120.54 concern aircraft-related paragraphs (a)(6) through (a)(9), not the paragraph (a)(5) encryption conditions discussed here.

That dated check resolves the specific amendment flag; it does not replace a complete export analysis. Keep the applicable classification, authorisation, recipient and current legal review with any real decision, particularly if the use or law changes.

Source context: State Department: Aircraft survivability equipment amendment · 22 CFR 120.54: Activities that are not exports

05

Keep unresolved access out of an approval conclusion

The fictional map below contains no controlled technical content. It shows a proposed AI route whose provider personnel, onward access and key handling have not been established. Its review outcome is unresolved until the accountable owner has the required facts and any necessary authorisation.

Use unrestricted synthetic material for a product evaluation. A security control can help enforce a defined policy on a supported path, but neither a blocked test nor this map determines export jurisdiction or grants an authorisation.

Source context: 22 CFR 120.33: Technical data · 22 CFR 120.50: Export

Put it into practice

Technical-data recipient and access map

A fictional engineering team maps a proposed AI service before considering a separate record that may be controlled. The controlled record is not included.

Synthetic system and recipient roles only. No controlled engineering content, real export classification, licence or authorisation is represented.

Follow the content and access
01

Source

Classification and intended purpose

02

Processing

Application and model recipients

03

Additional access

Support, logs, connections and intermediaries

04

Review

Locations, plaintext, keys and legal authority

Technical-data recipient and access map
Map pointFictional proposed routeQuestion before a real decision
Source recordEngineering document with classification unresolved.What is the actual jurisdiction/classification and supporting determination?
Employee deviceInput assembled on a managed device in the United States.Which local users and services can access the material?
Application operatorExternal AI interface sends content for model processing.Who is the legal recipient and what content can it read?
Model and hosting serviceProcessing location and authorised personnel are not established.Where is processing, and who can obtain plaintext or access information?
Support, logs and connected toolsPotential additional recipients and retained copies.What onward access exists, in which roles and locations, under which authority?
Encryption and keysTransport encryption is proposed; end-to-end conditions are unverified.Do actual key/recipient arrangements satisfy any relied-upon exception?
Review outcomeMaterial facts remain unresolved in this exercise.Do not treat the map as permission to transmit controlled material.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

itar-ai-recipient-access-map.mdInspect
# Technical-data recipient and access map

Synthetic system and recipient roles only. No controlled engineering content, real export classification, licence or authorisation is represented.

A fictional engineering team maps a proposed AI service before considering a separate record that may be controlled. The controlled record is not included.

| Map point | Fictional proposed route | Question before a real decision |
| --- | --- | --- |
| Source record | Engineering document with classification unresolved. | What is the actual jurisdiction/classification and supporting determination? |
| Employee device | Input assembled on a managed device in the United States. | Which local users and services can access the material? |
| Application operator | External AI interface sends content for model processing. | Who is the legal recipient and what content can it read? |
| Model and hosting service | Processing location and authorised personnel are not established. | Where is processing, and who can obtain plaintext or access information? |
| Support, logs and connected tools | Potential additional recipients and retained copies. | What onward access exists, in which roles and locations, under which authority? |
| Encryption and keys | Transport encryption is proposed; end-to-end conditions are unverified. | Do actual key/recipient arrangements satisfy any relied-upon exception? |
| Review outcome | Material facts remain unresolved in this exercise. | Do not treat the map as permission to transmit controlled material. |

## Review steps

- Establish data classification: Record the export-control determination and supporting basis for the actual information.
- Trace readable access and keys: Include model processing, support, logs, connections and intermediaries, not just hosting country.
- Resolve the authorisation or exception: Have the accountable export-control owner apply current requirements to the exact recipients and use.

## Unrestricted teaching input

“Rewrite a generic engineering-team meeting reminder.” No technical specifications, defence design or controlled information are provided.

## Fictional assessment record

Record: TECH-EX-29, not included.
Classification: unresolved in the teaching scenario.
Potential recipients: AI interface, model service, support/logging services and a security intermediary.
US hosting: a proposed fact, not an export conclusion.
Encryption exception: not established by a TLS label.
Authorisation: none represented.

## Source-currency note

FR Doc 2026-17660, published 28 August 2026 and effective 13 October 2026, changes aircraft-related paragraphs of 120.54. It does not amend the paragraph (a)(5) encryption conditions discussed in this exercise.

## Source and scope

Guide: https://aona.ai/resources/guides/itar-technical-data-ai-tools/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- 22 CFR 120.33: Technical data: https://www.law.cornell.edu/cfr/text/22/120.33
- 22 CFR 120.50: Export: https://www.law.cornell.edu/cfr/text/22/120.50
- 22 CFR 120.56: Release: https://www.law.cornell.edu/cfr/text/22/120.56
- 22 CFR 120.54: Activities that are not exports: https://www.law.cornell.edu/cfr/text/22/120.54
- State Department: Aircraft survivability equipment amendment: https://www.govinfo.gov/content/pkg/FR-2026-08-28/html/2026-17660.htm
Download itar-ai-recipient-access-map.md
itar-ai-recipient-access-map.csvInspect
Map point,Fictional proposed route,Question before a real decision
Source record,Engineering document with classification unresolved.,What is the actual jurisdiction/classification and supporting determination?
Employee device,Input assembled on a managed device in the United States.,Which local users and services can access the material?
Application operator,External AI interface sends content for model processing.,Who is the legal recipient and what content can it read?
Model and hosting service,Processing location and authorised personnel are not established.,"Where is processing, and who can obtain plaintext or access information?"
"Support, logs and connected tools",Potential additional recipients and retained copies.,"What onward access exists, in which roles and locations, under which authority?"
Encryption and keys,Transport encryption is proposed; end-to-end conditions are unverified.,Do actual key/recipient arrangements satisfy any relied-upon exception?
Review outcome,Material facts remain unresolved in this exercise.,Do not treat the map as permission to transmit controlled material.
Download itar-ai-recipient-access-map.csv

Before you proceed

Keep these distinctions clear

US hosting does not settle every release question
Assess the actual persons, entities and access as well as location.
Encrypted is not the complete exception
Review the precise end-to-end, recipient and other applicable conditions.

Apply it to employee AI use

Bring your actual data path.

Aona can be evaluated using unrestricted synthetic material for a defined employee input policy on a supported path.

It does not classify ITAR data, grant export authorisations or establish that a provider or processing route is permitted.

Keep actual controlled material out of the demonstration until the required contractual and export-control review authorises the real path.

Review your use case

FAQ

Questions for this decision

Does a US cloud region automatically make the use acceptable?
No. ITAR can also concern releases to foreign persons within the United States and other specified activities. Determine the actual recipients, access and applicable authorisation or exception.
Does ordinary TLS establish the end-to-end exception?
Not by itself. The regulation has specific encryption, decryption-access and other conditions. Map the actual plaintext and key boundary before relying on an exception.
Did the August 2026 amendment remove the encryption requirement?
The checked amendment concerns aircraft survivability equipment and changes aircraft-related paragraphs, effective 13 October 2026. It does not amend the paragraph (a)(5) encryption conditions discussed here.
Can this checklist approve an export?
No. It gathers facts for the responsible export-control and legal review. No licence, classification or authorisation is created by the worksheet or a security test.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. 22 CFR 120.33: Technical data

    ITAR technical-data definition and stated exclusions; a document label alone does not classify a real dataset.

    law · checked 2026-09-21
  2. 22 CFR 120.50: Export

    Export includes specified transmissions outside the United States and releases to foreign persons within the United States, subject to the stated exceptions.

    law · checked 2026-09-21
  3. 22 CFR 120.56: Release

    Technical-data release through the specified inspection, exchange and access-information circumstances.

    law · checked 2026-09-21
  4. 22 CFR 120.54: Activities that are not exports

    Conditional treatment of unclassified technical data secured with qualifying end-to-end encryption; third-party decryption and other conditions matter.

    law · checked 2026-09-21
  5. State Department: Aircraft survivability equipment amendment

    91 FR 55460 / FR Doc 2026-17660 is effective 13 October 2026 and revises aircraft-related paragraphs 120.54(a)(6)–(9), not the paragraph (a)(5) encryption conditions.

    law · checked 2026-09-21
ITAR technical data in AI: map the recipients | Aona