top of page

A practical guide to Export Controls

By Dr Martyn Taylor
Aug 25
13 min read

How to navigate Australia's export control regime in 2026


Based on my contribution to a panel session titled: "ITAR and Defence Export Controls" at the Southern Space 2026 conference in Canberra, Australia.  Thank you to my co-panelists from Department of Defence, EOS Space Systems, Saber Astronautics, and Lockheed Martin.


Key takeaways


  • Export controls now extend well beyond physical exports.  They can affect who may access technology, how information is shared, which components are used, international collaboration, investment and transactions.  Many technologies used in sectors such as the space sector have both civilian and military applications and may fall within dual-use controls.

  • Start with the technology. Know the products and services your business has and how they are classified.  Know who may access them.  Know where inputs came from. Australian and foreign controls may apply independently, particularly from the US.

  • Australia's regime has changed substantially.  The 2024 reforms extended controls to certain technology supplies within Australia, certain subsequent supplies outside Australia, and defence services. Meanwhile, the AUKUS licence-free environment reduces barriers for eligible trade between Australia. the United Kingtom (UK) and the United States (US).

  • Address export controls while choices remain open.  A component, access arrangement or information system can usually be changed more easily at the outset, rather than reconstructed or remediated years later. 

  • Export control capability can be a commercial asset.  Reliable classifications, technology records and access controls can make international collaboration and transactions easier and help businesses take advantage of available exemptions, including the AUKUS licence-free arrangements.


A practical case study: an Australian space start-up


For many Australian technology businesses, export control issues arise long before anything is physically exported. Consider an Australian space start-up developing a small satellite with an advanced sensing payload.  Some of the sensor, the on-board processing, the encryption, and the associated technical information may fall within dual-use controls, even though the company has never sold any military services.


The business collaborates with a university team that includes international researchers.  It hires foreign-national engineers.  It incorporates a specialised processor from a US supplier.  Its design files are held in a cloud repository accessible from three countries.  The founders plan to raise capital offshore, export the finished satellite, provide remote support from Australia and, eventually, sell the company.


Each of those decisions can have export control consequences.  Access to controlled technical information may be regulated.  A US-origin component may carry restrictions affecting later use or transfer.  Overseas access to a cloud repository may amount to a regulated supply of technology.  Those issues can remain relevant throughout the product's commercial life and surface again years later in due diligence.



The earlier these issues are identified, the more choices the business usually retains to manage them.  Australia's recent reforms make that more important.  Australia extended controls over additional supplies of technology and related activities, while also creating a licence-free environment for eligible trade with the US and UK under AUKUS.  For technology businesses, export control compliance now begins well before the first international shipment.


What are export controls and why are they relevant ?


Export controls protect military and sensitive technology, support international non-proliferation commitments and seek to prevent strategically important capabilities reaching potential adversaries.  Many technologies used by the military also have substantial civilian applications.  These are commonly described as “dual-use” technologies.  The space sector provides a particularly clear example.  Launch, propulsion, remote sensing, navigation, communications, optics, software and autonomous systems can all have both civilian and military applications.


The international system of export controls has developed over decades.  During the Cold War, Western governments coordinated restrictions on strategic exports through the Coordinating Committee for Multilateral Export Controls, or COCOM, which ceased operations in 1994.  Australia now participates in four major multilateral export control regimes.  The Wassenaar Arrangement addresses conventional arms and dual-use goods and technologies.  The Missile Technology Control Regime focuses on missiles and other unmanned delivery systems.  The Australia Group addresses technologies relevant to chemical and biological weapons proliferation.  The Nuclear Suppliers Group deals with nuclear materials, equipment and technology.


These regimes help coordinate national control lists, but each country implements export controls through its own domestic laws.  As such the same technology may need to be considered separately under Australian, US and other applicable regimes around the world.


The security objectives have remained broadly consistent.  However, strategically important technology is increasingly found in commercial products and digital information.  Sensitive capability can reside in software, technical data, components and know-how shared through international research, supply chains and information systems.  Australia's recent reforms respond to those circumstances by regulating additional supplies of controlled technology, including certain supplies within Australia.  At the same time, the AUKUS arrangements reduce licensing requirements for eligible technology sharing between Australia, the UK and the US.



How Australian export controls work


For Australian businesses, most export control issues can be worked through by asking four basic questions: what is controlled, what is being done with it, whether authorisation is required, and whether any additional controls apply.


The first question is classification.  The Defence and Strategic Goods List (DSGL) military and dual-use goods, software and technology that may be subject to Australian export controls.  Part 1, the Munitions List, principally covers goods, software and technology designed or modified for military use, together with certain non-military lethal items.  Part 2, the Dual-Use List, covers goods, software and technology generally used for commercial purposes but capable of military use, including in the development or production of military systems or weapons of mass destruction.  The DSGL is updated periodically, so classifications need to be kept under review. 


Classification is a technical exercise and requires knowledge of the nuances of the good or service.  Product knowledge is important.  Lawyers can apply the legal criteria, but engineers and other technical specialists will often need to establish what the product actually does.  For our start-up, that means understanding how the sensor, software and technical data fit within the DSGL.


The second question is the activity. Classification identifies the technology, but the legal consequence then depends on what the business proposes to do with it.  Physical exports of goods, software or technology speciied in the DGSL are regulated through the customs framework. 


The Defence Trade Controls Act 2012 (Cth) regulates intangible supplies of controlled technology, including exports from Australia to overseas.  Following the 2024 reforms, certain supplies of DGSL technology within Australia to foreign persons are also regulated. Certain subsequent supplies outside Australia of Part 1 items and items on the Sensitive and Very Sensitive Lists in Part 2 may also be regulated.  The latter can matter to multinational groups and distribution chains, because Australian controls can remain relevant after the original export.  The Act also regulates brokering, publication of certain military technology and specified services relating to Part 1 DSGL goods or technology.


The third question is authorisation.  Classification does not by itself establish that a permit is required.  The activity, parties and circumstances also matter.  Depending on the circumstances, exceptions and exemptions may apply. These include provisions concerning fundamental research, certain eligible persons and countries, persons holding specified security clearances, limited component-production activities, and the AUKUS licence-free environment.


The fourth question is whether other controls apply. An item falling outside the DSGL is not necessarily outside Australia's export control laws. Separate controls may apply under the military-end-use provisions of the Customs Act or Weapons of Mass Destruction (Prevention of Proliferation) Act. Australian and international sanctions must also be considered. 


The following is a practical decision tree for export controls:


  1. What is it? Identify and classify the goods, software or technology.

  2. What are we doing with it? Exporting goods, supplying technology, providing access or services, publishing, brokering or re-supplying?

  3. Who is involved, and where?  Identify the recipient, destination, end user and end use, and check applicable sanctions.

  4. What authorisation is required? Determine whether a permit is needed or a carve-out, exception, exemption or AUKUS licence-free pathway applies.

  5. What happens afterwards?  Keep the required records, control subsequent access and reassess the position when the technology, recipient, destination or use changes.


Foreign controls may apply within Australia


Australian compliance is only part of the analysis.  The US regulates defence articles, technical data and defence services under the International Traffic in Arms Regulations (ITAR). The Export Administration Regulations (EAR) in the US apply separately to a much broader range of commercial and dual-use commodities, software and technology.  The UK, European Union, Japan and other major technology-producing economies maintain their own regimes. Their jurisdictional rules, control lists and licensing requirements differ from those applying under US law. 


Australian and US classification need to be considered separately, as an Australian classification does not determine the US position, and vice versa.  US controls remain relevant after an item or technology has left the US.  Defence articles and technical data subject to ITAR, and commodities, software and technology subject to the EAR, can remain subject to US requirements governing subsequent re-exports, retransfers or releases.  The EAR can impose continuing restrictions in relevant circumstances. Supply contracts may also contain detailed restrictions concerning use, destinations, end users and subsequent transfers.  For an Australian business using US-origin technology, the original source and classification of an input can therefore affect what the business may later do with it.


Events in June 2026 illustrate how quickly US export controls can affect access to commercially important technology. According to Anthropic, on 12 June 2026, the US Government issues and export-control directive restricting foreign-national access to the recently released Claude Fable 5 and Claude Mythos 5 artificial intelligence models.  Anthropic suspended access to both models for all users because it said it had no reliable means of verifying nationality in real time. Anthropic subsequently reported that the controls were lifted on 30 June 2026 and access was later restored.


For our Australian space start-up, the US processor selected during product design may affect where the finished satellite can later be supplied and whether further US authorisation is required.  The same issue can arise with US-origin technical data used in developing the product.  For export control purposes, knowing where technology came from can remain important long after it has been incorporated into an Australian product.


Regulation can apply without a physical export


A regulated supply can occur without anything physically leaving Australia.  Following the 2024 reforms, certain supplies of DSGL technology within Australia to foreign persons have been regulated since March 2025.  That can include making controlled technology available to a foreign-national employee in Australia, although the activity is regulated only where the statutory elements are satisfied and no exception or exemption exists.  The concept has some practical similarities to the US deemed-export rules, which regulate certain releases of controlled technology to foreign nationals.


Employing a foreign national does not automatically require a permit.  The first question is whether the individual is a foreign person for the purposes of the Act.  An Australian citizen or permanent resident is a permanent resident for this purpose. A dual citizen who holds Australian citizenship is therefore an Australian person under the Act.  If the individual is a foreign person, the analysis then depends on the technology being supplied, how access is provided, and whether an exception or exemption applies.


Cloud systems also illustrate some of the complexities created by export controls.  The location of a server does not by itself determine whether a regulated supply has occurred.  What matters is whether DSGL technology is supplied to a person in circumstances covered by the Act.  Defence's guidance gives the provision of login credentials enabling access to DSGL technology as an example of how a supply can occur.  Technical support may involve a regulated supply of DGSL technology where that technology is disclosed in providing the support. It may also constitute a regulated DGSL service in certain circumstances.


For businesses, this brings export controls into decisions that might otherwise be treated as ordinary domestic recruitment or information technology matters.  Recruitment, contractor access, remote working and the configuration of information systems can all determine who is able to receive controlled technology.  For our Australian space start-up, the relevant questions arise when an engineer is given access to a design file, long before the finished satellite leaves Australia.


Australia - United Kingdom - United States (AUKUS) 


Australia's AUKUS licence-free environment removes Australian permit requirements for eligible transfers and activities involving Australia, the UK and the US, subject to the statutory conditions and excluded technologies.  The statutory conditions still apply.  Depending on the activity, these include requirements concerning the parties, location and technology, registration as an AUKUS authorised user through the My Australian Defence Exports (MADE) portal and pre-notification to Defence for specified exports and supplies from Australia.


The US has a corresponding exemption under the ITAR, introduced in 2024 and subsequently amended, including through a final rule effective in December 2025.  The UK operates its own corresponding arrangements.  Each country's requirements need to be considered separately.  Australian registration alone does not qualify a business to receive ITAR-controlled technology under the US exemption. Separate US certification as an "Authorized User" and compliance with ITAR section 126.7 are required.


There are also important exclusions.  Businesses using the Australian arrangements need to check the Excluded Goods and Technologies List and whether the item is covered by the Australian Military Sales Program, as well as the exclusions and limitations applying under ITAR section 126.7 and the corresponding EAR provisions where American-controlled technology is involved.  The exclusions include certain technologies relevant to missiles, launch and propulsion.  The position may change further. In May 2026, the three governments confirmed their support for expanding the licence-free environment through practical steps to narrow the list of excluded technologies. Their statement recorded a future commitment rather than an immediate amendment to the exclusions.


For eligible businesses, the commercial benefits of the AUKUS exemptions can be significant. Australia and the UK benefit from specific US exemptions that are not generally available to other US partners, subject to the eligibility conditions and excluded technologies.  Transactions that previously required individual permits may be able to proceed under the licence-free arrangements, but the business still needs to know what technology it holds, whether the parties and activity qualify, and what notification and record-keeping requirements apply.  Relevant Australian records generally need to be retained for five years.  A business that can establish those matters readily is better placed to use the AUKUS arrangements when an opportunity arises and to show US and UK partners that it can handle controlled technology appropriately.


Problems companies discover too late


Some of the most difficult issues arise because the relevant questions are not asked when the technology was first designed or acquired.


The first is product design.  A component selected because it is technically superior may also affect where the finished product can later be sold, manufactured, serviced or supported.  Where controlled technology is involved, classification and origin should be considered during relevant design reviews, while alternative components and architectures remain available.  A restriction identified at that point may be relatively easy to accommodate.  The same restriction discovered after the product has been developed, contracted or sold may be considerably harder to solve.


The second is commingling.  By year five, the Australian start-up's satellite platform may contain US-origin components and technical information, internally developed flight software, third-party modules, university-generated intellectual property and open-source code.  The question is no longer whether the product as a whole is controlled.  The business needs to know which technology is subject to which regime, where it came from and who may receive or access it.


Reconstructing that history years later can be difficult and expensive, particularly when the question first arises during due diligence.  The better approach is to create records as technology is developed or incorporated, while the engineers, supplier information and design history are still available.  That means maintaining classifications as designs change, recording the origin and relevant restrictions of material inputs, and appropriately segregating controlled technical information.


The third is transactions. Export control issues can be material in due diligence for defence, space and advanced-technology businesses.  Depending on the target and its technology, buyers may seek classifications, permits and other authorisations, technology-origin records and evidence concerning access to controlled information.


Identifying a restriction is only the beginning.  The next question is whether the transaction can proceed without disrupting the target's technology, people or operations.  That may require access to be segregated, an authorisation to be obtained before completion, or particular technology or activities to be dealt with differently.  An issue that could have been addressed relatively easily when the technology was first acquired can become a timing or deal-structure problem when it surfaces in the data room.


What businesses should do in practice


Getting it wrong can cost contracts, delay transactions, require expensive remediation and, in relevant cases, attract criminal penalties.  The most useful starting point, though, is simpler.

If there is one practical rule, it is this: know your product and technology.  Know what the business has, what it does, how it is classified, where it came from and who can access it.  Almost everything else follows from that understanding: whether a permit is required, whether foreign controls apply, whether an employee can be given access, whether an AUKUS exemption is available and what a buyer will want to see in due diligence.


A compliance program can then be organised around three disciplines.


  • Understand and classify it. Maintain an inventory of potentially controlled goods, software and technical information.  Classify them while the engineers who understand them are available, record their origin and identify any foreign controls that continue to apply.  Update classifications as designs change.  For start-ups and smaller businesses, doing this early matters.  Recording technology origin and separating controlled information is much easier while systems are being built than several years later.

  • Control access and movement. Map employees, contractors, affiliates and information systems against the restrictions applying to controlled technology.  Screen relevant end users and destinations.  Before an export, supply, service or other potentially controlled activity occurs, determine whether authorisation is required or an exception, exemption or AUKUS pathway applies.  Contracts should also capture the information the business will need later, including appropriate classification and origin information from suppliers and end-user information from customers.

  • Keep the evidence. Appoint someone clearly accountable, train the people who make relevant decisions and keep records that can still be retrieved years later.  Where the business relies on an exception or exemption, retain enough information to establish why it applied.  In a later audit or transaction, the difficult question is often why the business concluded, several years earlier, that a permit was unnecessary.


For businesses with greater exposure, periodic audits and an export control risk register may also be appropriate.  There should be a clear process for escalating potential non-compliance and difficult classification questions. Defence's guidance directs potential or suspected non-compliance to a Voluntary Disclosure Report submitted through the MADE portal.  Export controls also cannot be managed by legal or compliance teams alone.  Engineers select components, procurement teams deal with suppliers, human resources manages recruitment, information technology controls access, and commercial teams deal with customers and transactions.  Those functions need to know when an export control question should be raised.


Finally, keep the analysis current.  Revisit it when technology or designs change, a new controlled input is introduced, someone new requires access, information moves to a different system, a new country or end user is added, the product is re-exported or supported overseas, ownership changes, or the applicable control lists are amended.


Conclusion


Export controls are easiest to manage while choices remain open: before a component is selected, an engineer receives access to controlled technology, technical information is placed in a shared system or an acquisition data room opens.


Once those decisions have been made, the legal issue may still be manageable, but the business will often have fewer options and face greater cost.  For our space start-up, many of the important export control decisions will be made in design reviews, recruitment, information systems and contracts, long before the first satellite leaves Australia.


The common thread is understanding the technology: what the business has, where it came from, how it is classified, who can access it and where it may lawfully go.  That knowledge preserves commercial choices and makes later compliance, collaboration and transactions easier.  For a technology business, understanding its export control position has become part of understanding the business itself.

 

Authored by Dr Martyn Taylor, Partner & Board Member, Norton Rose Fulbright


Click to connect

Martyn Taylor is a lawyer at global law firm Norton Rose Fulbright based in Sydney.  He co-heads the telecommunications and media group (ranked Tier 1 in APAC), and the competition/antitrust and trade group (ranked Tier 1 in Sydney and Melbourne). He is described as “smart, efficient, friendly”.


Martyn’s practice covers transactional, contentious and advisory. He is a corporate and commercial lawyer and a well-known telecommunications, internet, media and technology (TMT), infrastructure/utilities, energy, competition and regulatory specialist.


Martyn has been endorsed as a 'top 10' TMT legal advisors in Asia.  He is recommended by the key legal directories, including Best Lawyers.  Recent awards include:

  • Australian Law Firm Partner of the Year - Competition, Trade & Regulation, 2023

  • Australian Law Firm Partner of the Year - Commercial, 2016, 2017, 2019, 2021

  • Australian Law Firm Partner of the Year - TMT, 2016, 2017, 2018, 2020, 2022

  • Best Utilities Project (Global) – World Bank Partnerships Awards, 2022 (Ethiopian telecoms rollout)

  • M&A Deal of the Year – Australasian Law Awards, 2016, 2021 (Vodafone/TPG merger)

  • Best M&A Deal - Finance Asia, 2020 (Vodafone/TPG merger)

 
 
bottom of page