When a European semiconductor manufacturer ships temperature sensors to a middleman in Singapore, who then sells them to a manufacturing facility in Iran, the exporter faces a critical question: which export control rules actually apply? The answer depends on whether the company is a US person, an EU resident, or subject to both frameworks — and the rules are not the same.
The European Union's dual-use export control system and the US Export Administration Regulations (EAR) both aim to prevent sensitive goods and technologies from reaching hostile nations, weapons programs, and proliferation risks. Yet they differ in scope, enforcement philosophy, and practical requirements. Compliance teams operating across the Atlantic must understand these differences to avoid the trap of assuming "if it's legal in one jurisdiction, it's legal in the other."
This post explains how the two regimes work, where they overlap, where they diverge, and what that means for compliance operations.
The Legal Foundations: EU Regulation vs. US Statute
The EU's control framework is built on EU Regulation (EC) No 428/2009 (the Dual-Use Regulation), which was substantially amended by Regulation (EU) 2021/821, effective since September 2021. This regulation governs the export, transit, and brokering of dual-use items and technologies from the EU to non-EU countries.
The US framework stems from the Export Administration Act and is operationalized through the Export Administration Regulations (EAR), codified at 15 CFR Parts 730–774. The EAR applies to all items "subject to the jurisdiction of the United States," including exports by foreign subsidiaries of US companies under certain circumstances.
Jurisdiction: The First Divergence
The EU Regulation applies to: - Export of dual-use items from EU territory to destinations outside the EU - Transit of certain sensitive items through EU territory - Brokering services arranged by EU residents, even if goods never touch EU soil
The EAR applies to: - Exports of US-origin items and technology to any destination - Exports of foreign-made items incorporating more than a de minimis amount of US content or technology - Reexports of controlled items (including foreign-made goods controlled under the Foreign Direct Product Rule) - Activities by US persons anywhere in the world
Critically, a German electronics company exporting a controlled item to China is subject to EU rules. A US person providing technical advice on that export is subject to EAR. These are parallel, not mutually exclusive, obligations. If both rules apply, compliance with the more restrictive standard becomes necessary — though that can create operational ambiguity.
Control Lists: Scope and Sensitivity Levels
Both regimes maintain control lists, but they differ in granularity and coverage.
The EU Control List (Annex I of Regulation 2021/821) is organized into ten categories: - Category 1: Special materials and related equipment - Category 2: Materials processing - Category 3: Electronics - Category 4: Computers - Category 5: Telecommunications and information security - Category 6: Sensors and lasers - Category 7: Navigation and avionics - Category 8: Marine technology - Category 9: Aerospace and propulsion - Category 10: Chemical, biological, and related precursor items
Each category includes a detailed list of items with technical specifications. Controls are triggered by combinations of parameters — for example, a semiconductor wafer fab is controlled if it meets specific technical thresholds for minimum feature size, throughput, and other specifications.
The US Commerce Control List (CCL) uses Export Control Classification Numbers (ECCNs) organized into ten Product Groups (0–9) spanning five broad categories (A–E). The ECCN system is more modular: a single item might be controlled for multiple reasons (national security, anti-terrorism, foreign policy, short supply, crime control) with different license requirements depending on the end-use and end-user.
Practical Difference
An item might be controlled under the EU list for a particular sensitive parameter but fall below the EU technical threshold, while the same item is controlled under an ECCN for national security reasons. Conversely, an item controlled in the US might not appear on the EU list. This means screening a single shipment against both lists is essential — you cannot assume parallel control.
License Requirements and Thresholds
The EU and US diverge significantly on when a license is actually required.
The EU Approach: Destination-Based Gating
The EU Regulation divides non-EU countries into two categories: - General destination countries: Exports to most nations require a general license (automatic approval, no application) unless the exporter suspects an end-use related to weapons of mass destruction, missiles, or military purposes (the "catch-all" rule). - Sanctioned/sensitive destinations: Exports to certain countries (currently including Iran, North Korea, Syria, and others) may require an individual license for controlled items, regardless of end-use.
Additionally, the EU maintains strict anti-proliferation catch-all controls: if an exporter has reasonable grounds to suspect an export will contribute to WMD development, a license is required even if the item itself is not on the control list.
The US Approach: End-Use and End-User Driven
The EAR requires a license for most controlled items regardless of destination — unless an exclusive end-use license exception (like the License Exception ENC for encryption or License Exception GFE for government end-use) applies. The US maintains a far more expansive list of end-uses requiring licensing: - Military end-use or military end-user (even in allied nations) - Nuclear proliferation - Chemical or biological weapons - Missile technology - Unsanctioned foreign policy purposes (e.g., items for foreign military end-use when US policy opposes such transfers) - Encryption for encryption-specific items
The Wassenaar Arrangement coordinates control lists across 42 countries (including EU members and the US), but national implementations differ. The US typically maintains longer control lists and lower thresholds than EU members.
The "Deemed Export" Problem
A critical operational divergence: the EAR imposes deemed export liability on US persons who disclose controlled technical data or source code to foreign nationals, even within US territory. Sharing a technical whitepaper on semiconductor design with a Chinese engineer inside a US office triggers deemed export obligations.
The EU Regulation does not impose a deemed export rule. Technical data is controlled as its own category, but the control applies to the act of transfer outside the EU, not to disclosure within the EU. This creates asymmetric risk for multinational teams: a European headquarters can legally hold design documents that a US subsidiary cannot legally email to a foreign national.
Licensing Procedures and Processing Times
EU Licensing
EU member states each operate their own licensing authority. A German exporter applies to the Federal Office of Economics and Export Control (BAFA). The EU regulatory framework sets minimum standards, but member states retain discretion in implementation.
- Processing times vary by member state (typically 15–60 days for standard applications)
- The exporter bears the burden of proving items fall outside the control list or qualify for a general license
- Decisions are not harmonized; one member state's approval does not guarantee another's
US Licensing
The US BIS operates a centralized licensing system. All applications go to a single entity.
- Standard processing is ~30 days; some cases take 60–90 days or longer for interagency review
- The burden of proof is on the applicant to demonstrate compliance
- Decisions are uniform across all destinations and end-users
- License applications require detailed factual statements about end-use, end-user, and foreign consignees
The US system is slower but more transparent; the EU system is faster but more fragmented.
The Catch-All Controls: Intentionality and Proof
Both regimes include catch-all rules designed to prevent circumvention when an exporter suspects a shipment supports proliferation or weapons development. Yet they differ critically in the triggering standard.
The EU catch-all is triggered if the exporter has "reasonable grounds to suspect" an export will be used for WMD, missiles, or — under amendments effective 2021 — military end-use in destabilized regions. The definition of "reasonable grounds" is fact-based and subjective; compliance teams must document how due diligence was conducted.
The US catch-all for foreign policy is discretionary with the President and EAR Section 6(a); the WMD catch-all requires actual knowledge of WMD end-use. The US standard is generally higher: suspicion alone is insufficient; knowledge of the prohibited end-use must be demonstrated.
This creates operational friction: a transaction may trigger EU catch-all obligations but not EAR catch-all obligations, forcing the exporter to seek an EU license while the US transaction proceeds without one.
Sanctions Integration: Overlapping but Separate
Neither the EU Regulation nor the EAR is a sanctions regime in the traditional sense. However, both integrate sanctions controls into licensing decisions.
The EU references CFSP sanctions decisions and maintains consolidated lists of sanctioned destinations and persons. An export to a sanctioned entity is typically prohibited outright; no license will be issued.
The US EAR cross-references OFAC sanctions, but the EAR license and the OFAC license (if applicable) are separate. A transaction might require both a BIS license and an OFAC license, or neither, depending on the items, destination, and end-user. Confusingly, some OFAC-designated entities appear on the BIS Entity List (triggering EAR restrictions) while others do not.
Practical Compliance Implications
For operations teams managing transatlantic trade, these differences create four recurring challenges:
1. Dual Screening Requirements
A single shipment must be screened against three standards: - Does it require an EU license? - Does it require a US EAR license? - Are there overlapping or conflicting requirements?
Best practice: maintain a unified control matrix that maps items to both control lists, identifies which list is most restrictive, and documents the licensing path for each transaction.
2. Supply Chain Complexity
A German semiconductor supplier shipping to Singapore (then to end-customer in Iran) faces: - EU export control liability if the shipment triggers the EU Regulation - Potential US liability if the supplier is a US person or the items incorporate US technology above the de minimis threshold - Risk of EU license denial if end-use in Iran is disclosed
The Singapore intermediary may not know the true end-use, forcing the original exporter to conduct diligence on an opaque supply chain. Document retention and audit trails are critical.
3. Technology Disclosure in Multinational Teams
US subsidiaries and foreign nationals in the US cannot legally receive deemed exports of controlled technical data. EU teams do not face this restriction. Operational divisions must exist: US teams cannot design and develop alongside non-US persons unless the data is authorized for export. This often requires: - Separate code repositories - Restricted access to design documentation - Certification that disclosed data falls below EAR control thresholds
4. License Application Harmonization
When both US and EU licenses are required, the applications must be consistent. Applicants sometimes apply for different end-uses or end-users in the two jurisdictions, creating liability for misrepresentation. Submit parallel applications with identical factual statements; if the end-use differs, reassess whether both licenses are truly required.
What Compliance Teams Should Do
- Map your supply chain against both control lists. For each product line, determine which items trigger EU controls, which trigger US controls, and which trigger both. Maintain this matrix in your compliance platform.
- Establish licensing workflows that test both regimes. Before submitting an application, confirm that the same facts support a favorable determination under both frameworks. If not, reconsider the transaction or seek clarification from the authorities.
- Document deemed export risks. If your organization includes US persons and non-US persons, implement access controls on technical data. Audit your email systems and design repositories for unauthorized sharing of controlled data to foreign nationals.
- Coordinate with your EU and US counsel. Do not assume one regime's approval will simplify the other. Engage legal counsel in both jurisdictions before large transactions.
- Monitor regulatory changes. The EU Regulation was substantially updated in 2021; further amendments are likely. The US maintains a more active amendment cadence. Subscribe to official alerts from BIS and your relevant EU member state authority.
- Conduct end-use diligence consistently. Whether EU or US rules apply, verify the stated end-use and end-user independently. False statements or knowledge of misuse are criminal under both frameworks.
Export controls operate in parallel universes: the EU and US regulations are designed to achieve similar policy goals but use different legal mechanisms, different lists, and different enforcement standards. Compliance teams must operate in both universes simultaneously, treating the more restrictive rule as the binding standard. This demands investment in control matrices, legal expertise, and due diligence discipline — but the cost of non-compliance across jurisdictions is substantially higher than the cost of preventive compliance.