
Export control is no longer only about physical shipments. For advanced technology companies, sensitive capability can move through AI tools, cloud environments, prompts, outputs, logs, customer demos, contractors and foreign-person access.
This checklist helps technical and commercial teams identify where their access-control architecture may create export-control exposure before it becomes urgent.
Who this is for
- Deep-tech companies
- Defence and dual-use startups
- Aerospace and space companies
- AI infrastructure, model and cloud teams
- Semiconductor, photonics and advanced manufacturing teams
- Companies preparing overseas customer demos, bids, pilots or fundraising
The 72-hour test
Could your team restrict access by user, country, customer, project and data class within 72 hours?
If not, the issue is not only legal awareness. It is system design.
1. Controlled technical data
2. AI tool usage
3. User and foreign-person access
4. Demo and customer environments
5. Incident and revocation readiness
6. Commercial readiness
How to read your answers
If several answers are unclear, the risk is probably not the regulation itself. It is that your technical and commercial systems were not designed with export-control boundaries in mind.
Borie Consulting helps advanced technology companies turn export-control uncertainty into practical operating decisions before they export, bid or raise.
This checklist is a scoping tool. It is not legal advice.