EAR and ITAR are the two US export-control regimes that govern international research collaboration, administered by the Commerce Department (BIS) and State Department (DDTC). Most academic research stays outside both under the fundamental research exclusion, but that protection breaks down once a project involves controlled technical data — triggering deemed-export rules for foreign national collaborators.
This is not legal advice. Export control determinations are fact-specific and consequential (civil penalties, debarment from federal funding, and in willful cases criminal liability), and every institution doing federally sponsored or dual-use research should have a designated Empowered Official or export control officer making the actual classification calls. What follows is the operational shape of the problem, sourced to the actual regulatory text, so a research administrator knows what questions to ask and when to escalate.
Why the fundamental research exclusion matters for universities
Most university research never touches export control at all, because of a specific, deliberately protected carve-out. Under National Security Decision Directive 189 (NSDD-189, issued 1985, reaffirmed by the White House in 2001), the default US policy position is that the products of federally funded fundamental research should remain unrestricted “to the maximum extent possible.” Both EAR and ITAR incorporate that policy directly into their own regulatory text rather than treating it as external guidance:
- EAR (15 CFR §734.8): technology or software that “arises during, or results from” fundamental research and is intended to be published is not subject to the EAR at all — it falls outside the regulation’s scope entirely, not merely under a license exception.
- ITAR (22 CFR Part 120’s public-domain/fundamental-research definitions, administered by DDTC): basic and applied research in science, engineering, and mathematics is excluded on the same NSDD-189 logic, where results are ordinarily published and shared broadly within the research community.
The reason this matters so much operationally is that the exclusion is conditional, not automatic, and the condition is entirely within an institution’s control: research stops qualifying as fundamental research the moment the university or its researchers accept a restriction on publication, or accept government-imposed access and dissemination controls tied to a sponsor’s national-security concerns. A grant, contract, or material transfer agreement that lets a sponsor review a manuscript before submission is generally fine if the review is for confidentiality of the sponsor’s own proprietary information and doesn’t function as a veto over what gets published; a clause that lets the sponsor restrict publication outright, or that excludes foreign nationals from the research team as a condition of participation, forfeits the exclusion for that project. This is why sponsored-programs offices flag “no foreign nationals” and “publication approval” clauses during contract review before a PI ever signs — not as a formality, but because signing one converts a project that would otherwise sit entirely outside EAR/ITAR into one that doesn’t.
When export-controlled technology, software, or technical data crosses that exclusion
The fundamental research exclusion protects the results of open research — it does not automatically protect every input, tool, or component used to get there. A project can be conducting genuine fundamental research and still have an export control exposure sitting inside it. The practical trigger points research administrators watch for:
- Controlled equipment or software brought into an otherwise-open project. A piece of lab equipment, a simulation code, or an encryption library that is itself export-controlled (has an Export Control Classification Number, or ECCN, under the EAR, or appears on the US Munitions List under ITAR) doesn’t lose its controlled status just because the surrounding research is publishable. Using it, or letting a foreign national operate it, can trigger a control independent of the fundamental research exclusion.
- Proprietary or government-furnished inputs. Data, specifications, or materials supplied by a sponsor under a non-disclosure or specific access-control agreement (common with defense-adjacent or classified-adjacent funding) stay controlled even when the rest of the project publishes normally — the exclusion is scoped to what “arises during or results from” the research, not to everything touching the project.
- A shift from basic/applied research to design, production, or product development. NSDD-189 explicitly distinguishes fundamental research from “industrial development, design, production, and product utilization” — a project that moves from studying a phenomenon to engineering a deliverable (a prototype, a working device meeting a sponsor’s specification) can move out of the exclusion’s scope even without a new publication restriction being added.
- Pre-publication technology, before publication actually happens. The EAR’s own text is specific on this point: technology “arising during” fundamental research is only excluded to the extent researchers are free to publish it without restriction — the exclusion covers the freedom to publish, not a guarantee that publication has already occurred. Between the point a controlled input is used and the point results are actually released, an institution can still have export control obligations for how that intermediate technology is handled and who has access to it.
In practice, this is why export control review is a classification exercise at the start of a project (what’s actually being brought in, funded, or built) rather than a one-time check of whether the eventual paper will be publishable.
Deemed-export rules for foreign national researchers
The piece of export control that catches research administrators most often isn’t shipping anything overseas at all — it’s what happens inside a US lab. Under the EAR’s deemed export rule (15 CFR §734.13(a)(2)), releasing controlled technology or source code to a foreign person anywhere in the United States is treated as an export to that person’s most recent country of citizenship or permanent residency — not their country of birth, and not the country they’re currently studying or working in. A closely related deemed reexport rule (15 CFR §734.14) applies when controlled technology is released to a foreign person of a country other than the one where the release physically occurs.
“Release,” under the EAR, is defined broadly enough to catch situations that don’t look like an export at all: visual inspection of controlled equipment or documents by a foreign person, verbal or written technical discussion, and — explicitly — email and screen-shared video calls. A foreign national graduate student watching a demonstration of controlled instrumentation, or being copied on a technical email thread about it, can constitute a release just as much as physically handing over a controlled document.
Two things narrow this considerably in practice, and are worth stating precisely rather than approximately:
- The deemed export rule doesn’t apply to lawful permanent residents, US citizens, or persons granted “protected individual” status under US immigration law — the rule is specifically about foreign persons, defined by citizenship/permanent-residency status, not about nationality of origin, and not about most visa holders once a green card is obtained.
- The fundamental research exclusion, where it genuinely applies, covers this too. If the underlying technology qualifies as excluded fundamental research in the first place (see above), there’s typically nothing controlled to “release” via deemed export, because it was never subject to the EAR to begin with. Deemed export risk concentrates specifically where a project has already crossed out of the exclusion, or where the controlled item is a discrete input (equipment, software, a defense article) rather than the open research output itself.
Where deemed export exposure is real, institutions manage it through a Technology Control Plan (TCP) — a documented set of physical, IT, and procedural restrictions (badge-access lab areas, segregated network shares, supervised-access-only for specific instruments) scoped to the individual foreign national and the specific controlled item, rather than a blanket restriction on international lab members. A visiting scholar or postdoc from a country with additional restrictions may need a deemed export license before ever being given unsupervised access to a controlled dataset or instrument — this is a real, non-trivial timeline item for any international hire or visiting-researcher placement onto a project with known controlled content, and it needs to be identified during the visa/onboarding process, not discovered after the person has already started work.
Practical compliance steps for international research collaboration
None of the above is manageable case-by-case at the point of crisis — it needs to be built into how an institution stands up an international collaboration in the first place.
- Classify before you commit. Before signing a sponsored agreement, MTA, or subaward involving foreign collaborators, determine whether any equipment, software, data, or specifications involved carry an ECCN or USML classification, and whether the agreement itself imposes publication or access/dissemination restrictions that would forfeit the fundamental research exclusion. This is a job for the institution’s export control officer or Empowered Official, not the PI alone — get it done at proposal stage, not after award.
- Screen collaborators and institutions against restricted party lists. Before adding a foreign collaborator, subawardee institution, or visiting researcher to a project, screen them against BIS’s Entity List, Denied Persons List, and Unverified List, OFAC’s Specially Designated Nationals (SDN) list, and DDTC’s Debarred Parties list. A restricted-party hit doesn’t automatically bar collaboration, but it changes what’s permissible and often requires a license.
- Flag contract clauses that forfeit the exclusion during review, not after signature. “No foreign nationals,” “sponsor pre-approval of publication,” and “specific access/dissemination controls” clauses are the three patterns sponsored-programs offices train reviewers to catch, because any one of them can move a project out of the fundamental research exclusion regardless of how open the science itself is.
- Put a Technology Control Plan in place before, not after, a foreign national gets access. If the classification step above identifies controlled equipment, software, or data, scope a TCP to the specific individual and item, and route any deemed export license need through the export control office with enough lead time — this is one of the more common sources of preventable delay in bringing on an international postdoc or visiting scholar.
- Disclose foreign support and affiliations accurately, separately from export control itself. Federal funders increasingly require disclosure of all foreign and domestic research support, in-kind resources, and affiliations as part of research security requirements under National Security Presidential Memorandum 33 (NSPM-33) and agency-specific policies (for example, NSF’s Research Security Training requirements and NIH’s disclosure requirements). This runs alongside export control compliance, not instead of it — a project can be fully compliant on export control and still be non-compliant on disclosure, or vice versa.
- Train the people actually running the collaboration. PIs, lab managers, and international-program staff need enough working knowledge to recognize a deemed export or classification trigger in real time — waiting for the export control office to catch every case after the fact isn’t a reliable control, since a release under 15 CFR §734.13 can happen in an ordinary lab conversation or email thread with no paper trail forcing a review.
How this fits into the broader research security picture
Export control compliance is one piece of a wider research security framework that has expanded substantially in recent years, and treating it in isolation from the rest of that framework is a common practical mistake. CASRAI’s Dictionary covers several of the adjacent concepts a compliance program needs alongside export control specifically: research security policy broadly, the UK’s parallel Trusted Research framework (the UK government’s non-regulatory equivalent to the US fundamental research exclusion conversation), the Five Eyes alliance‘s role in coordinated research-security guidance, and the JASON report on research security that shaped much of the current US federal policy direction, including NSPM-33. Institutions that build export control review, restricted-party screening, and foreign-support disclosure into a single coordinated process — rather than three separate offices each checking their own piece — catch cross-cutting issues (a restricted-party hit that’s also a disclosure gap, for instance) that a siloed review misses.
Frequently asked questions
Does getting NIH or NSF funding automatically trigger export control review?
No. Federal funding alone doesn’t create an export control obligation — most federally funded basic and applied research qualifies for the fundamental research exclusion precisely because it’s openly published. What triggers review is the presence of a specific controlled input (equipment, software, technical data) or a contractual restriction on publication or access, not the funding source itself.
Can a foreign national student or postdoc ever work on an export-controlled project?
Sometimes, but it requires a deemed export license or a Technology Control Plan scoped to that individual and the specific controlled item — it isn’t a blanket bar. Lawful permanent residents, US citizens, and protected individuals aren’t subject to the deemed export rule at all. The practical issue is usually timeline: a license determination needs to happen before the person gets access, not after.
If our university only does basic research and never handles classified information, do we still need to worry about ITAR?
Possibly, if any project uses equipment or technical data that independently carries a US Munitions List classification, or if a sponsor’s agreement imposes access/dissemination controls — classification status attaches to specific items and contract terms, not to an institution’s general research posture. The safest practice is a classification check at proposal stage for any project involving defense-adjacent sponsors, dual-use technology, or foreign collaborators, rather than assuming “we’re a university” is itself protective.
What’s the difference between export control review and the newer research security disclosure requirements (NSPM-33)?
They’re related but legally distinct. Export control (EAR/ITAR) governs the transfer of specific controlled items, software, and technical data to foreign persons or destinations. NSPM-33 and its implementing agency policies govern disclosure of foreign and domestic research support, affiliations, and participation in foreign talent recruitment programs, largely independent of whether any given project touches a controlled item at all. A well-run compliance program tracks both, because they’re reviewed by different offices but can surface overlapping facts about the same collaboration.
Who makes the actual export control determination at a university?
Typically a designated Empowered Official (the ITAR/DDTC term) or export control officer within the sponsored-programs or research-compliance office, not the individual PI — precisely because classification determinations carry institutional liability and require specialized regulatory knowledge that changes with each new item, sponsor, and country involved.







