
Recent reports suggest that BIS is considering eliminating a “loophole” under which China remotely accesses in foreign countries high-performance AI servers that could not themselves be exported to China. That would not be eliminating a loophole; rather it would be a departure from a longstanding policy.
BIS’s authority is described in, and constrained by, the Export Control Reform Act. It grants BIS the authority to regulate the “export, re-export, and in-country transfer” of a “commodity, software or technology.” Technology is defined as “information, in tangible or intangible form, necessary for the development, production, or use of an item.” These restrictions are the same as those found in prior authorizing statutes.
In 2009, BIS made clear in an advisory opinion, relying on these statutory definitions, that remote access and cloud computing did not constitute an export within its regulatory jurisdiction. The access alone, it reasoned, “is not shipping or transmitting any commodity, software, or technology.”
The advisory opinion also dismissed the notion that this remote access alone could violate section 744.6(a)(2) of the EAR. That provision, authorized under section 1754 of the Export Control Reform Act, states that a U.S. person must obtain a license from BIS before performing any service that the U.S. person knows will directly assist in the design, development, production, or use of missiles in or the design, development, production, stockpiling, or use of chemical or biological weapons. That test will not be met by the foreign server provider only in the unlikely event that it has direct knowledge of such use by its customer. Also, and even more importantly, the foreign server provider is not a U.S. person.
If you think that remote access might be a transfer of “use” technology which could be controlled by BIS, the agency cut off that pathway as well all the way back in 2004. The agency said the mere operation of a dual use item by a foreign national is not a deemed export; rather, a deemed export occurs only when the foreign national is given information that would permit the foreign national to engage in all six activities defined as use, namely “[o]peration, installation (including on-site installation), maintenance (checking), repair, overhaul and refurbishing.”
Look, I get the desire to limit China’s access to advanced computing resources. I do. But the proverbial horses have already escaped the proverbial barn and are grazing in fields of advanced computing power all over the world. And, how exactly is BIS going to root out violations? How will it know that the Chinese are accessing an advanced computing resource in the Duchy of Grand Fenwick or in a server farm in Uqbar?