WEBVTT

00:00:00.000 --> 00:00:03.169
How can companies navigate
evolving export control rules

00:00:03.169 --> 00:00:04.337
in the US?

00:00:09.759 --> 00:00:10.343
Today,

00:00:10.343 --> 00:00:12.012
many companies store
and process

00:00:12.012 --> 00:00:13.638
their information
in the cloud,

00:00:13.638 --> 00:00:16.349
which means that export
controlled source code,

00:00:16.349 --> 00:00:18.351
object code, and
other technical data

00:00:18.351 --> 00:00:21.312
can transfer seamlessly across
borders at a rapid pace,

00:00:21.312 --> 00:00:22.897
and data and software
can be stored

00:00:22.897 --> 00:00:25.316
in the cloud virtually
anywhere in the world.

00:00:25.567 --> 00:00:28.153
However, the definition of
what constitutes an export

00:00:28.153 --> 00:00:28.903
under US law

00:00:28.903 --> 00:00:31.197
predates the advent of
modern technology.

00:00:31.197 --> 00:00:33.533
To address this gap,
starting in 2009,

00:00:33.533 --> 00:00:35.076
the Bureau of Industry and Security

00:00:35.076 --> 00:00:37.704
issued a series of rules that
address how export controls

00:00:37.704 --> 00:00:39.247
apply to modern
cloud computing.

00:00:44.377 --> 00:00:46.796
Companies should know
that in January 2026,

00:00:46.796 --> 00:00:49.299
the House passed the
Remote Access Security Act,

00:00:49.299 --> 00:00:50.508
which would authorize BIS

00:00:50.508 --> 00:00:52.802
to regulate the remote
access to items subject

00:00:52.802 --> 00:00:54.262
to US export controls.

00:00:54.554 --> 00:00:56.431
One of the key aims
of the act is to close

00:00:56.431 --> 00:00:58.349
what Congress and the
regulators perceive to be

00:00:58.475 --> 00:01:00.185
a loophole in the
export control rules

00:01:00.185 --> 00:01:02.604
that lets foreign entities
remotely access

00:01:02.604 --> 00:01:04.814
advanced US chips in
data centers that they would

00:01:04.814 --> 00:01:06.566
otherwise
not be able to obtain.

00:01:11.905 --> 00:01:13.448
Because export control
rules around

00:01:13.448 --> 00:01:15.408
cloud computing
are very fact-specific,

00:01:15.575 --> 00:01:17.410
companies must ensure
they understand the rules

00:01:17.410 --> 00:01:19.370
before they proceed
with cloud transactions

00:01:19.370 --> 00:01:21.623
involving export-controlled software,

00:01:21.831 --> 00:01:23.583
source code, and technical data.

00:01:23.583 --> 00:01:25.168
Experienced counsel
can help companies

00:01:25.168 --> 00:01:27.045
avoid risk and
stay compliant

00:01:27.045 --> 00:01:29.172
amid an evolving
regulatory landscape.

00:01:29.214 --> 00:01:31.257
At Latham, we pair
our deep expertise

00:01:31.257 --> 00:01:33.760
in export controls across
cloud computing,

00:01:33.802 --> 00:01:36.971
AI infrastructure,
semiconductors, and software

00:01:37.138 --> 00:01:39.557
with practical government
experience to help clients

00:01:39.557 --> 00:01:42.769
design compliant architectures,
policies, and transactions

00:01:42.769 --> 00:01:44.270
aligned with their
business goals.

00:01:44.479 --> 00:01:46.439
I’m Aaron Amundson,
I’m Counsel at Latham,

00:01:46.439 --> 00:01:47.899
and former Director of BIS’s

00:01:47.899 --> 00:01:49.818
Information Technology
Controls Division,

00:01:49.818 --> 00:01:52.112
and I’ve been advising
on the full spectrum of US

00:01:52.112 --> 00:01:54.114
export control matters
for more than 20 years.