Publication is not a Panacea

By Sudarsanan Sivakumar, Law Clerk

Some people think publishing source code is sufficient to evade export controls. It is not.

Publication on its own is never sufficient. While the International Traffic in Arms (“ITAR”) regulations indicate that information in the public domain that is published and that is generally accessible or available to the public is excluded from control as ITAR technical data, such information has to be made available only according to 22 CFR 120.11 or with the explicit authorization of the United States Department of State (“State Department”). See, 22 CFR 120.34(a)(7) and 22 CFR 125.4(b)(13).

The Export Administration Regulation (“EAR”), on the other hand, generally excludes all open-source software that is published and publicly available from export control restrictions. Specifically, EAR § 734.3(b)(3)(i) states that information and software that “are published, as described in § 734.7” are not subject to the EAR. Common examples are publicly available source code and libraries that are published. However, even under the EAR, publication may be problematic.

For example, EAR §742.15 (b) states that the BIS should be notified by email for publicly available encryption source code classified under ECCN 5D002 that performs “non-standard cryptography.” An example of standard cryptography is TLS.
It’s important to understand that simply publishing open-source software does not exempt one from complying with U.S. export control laws. Even if someone published in accordance with EAR § 734.7 and 742.15, they could still violate other export control laws.

The September 11, 2009, BIS Advisory Opinion dealt with the question of whether an export control violation takes place if mass market encryption software can be downloaded free of charge without restriction. BIS provided examples that it can violate the requirement to “Know Your Customer,” codified at 67 Fed. Reg. 38857, June 6, 2022.

Another example is in the dual-use scenario. Published algorithms will not free other algorithms that are used on a project from export controls. An example would be that software designed for missile guidance will still be subject to export control laws.

Legal issues differ based on situations. If you want to discuss how the open-source world, as it relates to export controls, impacts you, reach out to the author or to your Centre attorney.

 


1See, “eCFR :: 15 CFR 734.7 — Published.

Share
LinkedIn
X
Facebook