Managing Export Control Risks in AI Model Procurement

by Zachary Barlow

July 28, 2026

If you’re shopping around for AI models, there are pretty much only two countries to source from: the United States and China. Export control rules apply to data, even without the import or export of physical products, and that includes AI models. Export control risks for AI vary depending on where your company operates and which AI model you’re using. A recent Sheppard memo goes in depth on the risks presented by both U.S. and China-based AI models. First, the memo notes that US export controls often pull products or require licenses with no formal rulemaking:

“Here is the pattern that should shape your planning: U.S. restrictions on AI arrive fast, often without any published legal instrument, while reversals come slowly or through litigation. The switch flips instantly. Flipping it back on requires a lawsuit.”

If your company is using AI in its international operations, the possibility of a widespread disruption at the flip of a switch might give you pause. However, the memo makes clear that Chinese models carry their own risks, particularly if your company operates within the U.S.:

“Adopting Chinese models raises four distinct categories of U.S. legal exposure, plus a revocability risk of their own. First, export controls on what you put into the model. Prompting a model hosted in China, or operated by a Chinese provider, with technology subject to the EAR or ITAR technical data is best analyzed as an export or release to China, requiring authorization in most cases.”

The memo also notes that even the Chinese models without EAR or ITAR restrictions may utilize underlying restricted software or hardware. Companies will need to examine their specific use cases and weigh which models to use carefully. Mitigating export control risks for AI may involve using multiple models across your workflows. Altering where and how AI is used based on geographic operations.