Two facts sit uncomfortably next to each other, and most people find both of them backwards.
First: the exploits are not the controlled thing. BIS's own FAQ on the cyber rule, question 24, says it plainly (BIS FAQs, rev. Feb 2022):
"Neither the disclosure of the vulnerability nor the disclosure of the exploit code would be controlled under the rule."
That holds even when the disclosure is private and unpublished. Layer on 15 C.F.R. § 734.7, under which published technology and software fall outside the EAR's scope entirely (eCFR), and the EU's mirror concept — Annex I's General Technology Note, which exempts information "in the public domain," defined as technology or software "made available without restrictions upon its further dissemination," with copyright restrictions expressly not disqualifying.
Second: the shipment is the controlled thing, and there is no shipment. Regulation (EU) 2021/821 Article 2(2) defines "export" to include (consolidated text) "transmission of software or technology by electronic media, including by fax, telephone, electronic mail or any other electronic means to a destination outside the customs territory," making it available electronically to persons outside the customs territory, and even "oral transmission of technology when the technology is described over a voice transmission medium."
Uploading a corpus to a US lab's bucket is an export event. So is explaining a technique on a call with a buyer's research team. There is no crate, no customs declaration, no broker, and no natural moment at which anyone in the company notices that an export has occurred.
Restrict the corpus to published, patched vulnerabilities, and one discipline does five jobs at once. It supports the EAR "published" and EU "in the public domain" arguments. It matches the ethical position benchmark authors already take. It removes the worst misuse case. It removes any coordinated-disclosure obligation, because disclosure already happened. And it is the precondition for an insurer writing the risk at all — see Nobody prices this risk yet. No other single decision in this business buys as much.
What is actually controlled
The 2013 Wassenaar plenary added controls on "intrusion software" by controlling not the software itself but the systems, equipment, software and technology for generating, commanding and controlling, or delivering it. BIS's first attempt to implement this in the US — the proposed rule of 20 May 2015 — provoked an industry revolt and was withdrawn; the 2017 plenary added exemptions for vulnerability disclosure and incident response (Lawfare). The operative US rule today is the interim final rule of 21 October 2021 as revised by the final rule effective 26 May 2022.
| Entry | What it catches | Relevance to a corpus business |
|---|---|---|
| 4A005 | Systems and equipment specially designed to generate, command-and-control or deliver intrusion software | Only if you build delivery infrastructure |
| 4D004 | Software specially designed for those functions | C2 frameworks, implants, loaders built to produce the data |
| 4E001.a | Technology for development, production or use of 4A005/4D004 items | Documentation and know-how for the above |
| 4E001.c | Technology "for the development of intrusion software," with carve-outs for vulnerability disclosure and incident response | The entry a corpus would be argued into, if any |
"Intrusion software" means software designed to avoid detection by monitoring tools while extracting or modifying data on a target without authorisation. The EU's Annex I mirrors all four entries; Article 11 requires authorisation for intra-EU transfers only of Annex IV items, so ordinary Annex I items move freely inside the Union — which matters if contractors are spread across member states, as Where the supply can legally live assumes.
License Exception ACE (15 C.F.R. § 740.22) authorises licence-free export of these items to non-government end users outside Country Groups D:1 and D:5, to US subsidiaries, and to financial, insurance and medical organisations anywhere. It is unavailable for Country Groups E:1/E:2 and for government end users in D:1–D:5. The May 2022 final rule also narrowed a permission for exports to police bodies down to "digital artifacts" for specific investigations, and rewrote the "government end user" definition to treat 25%-or-more beneficial ownership or board-appointment control as government ownership.
ACE cannot be used where the exporter knows or has reason to know the item will be used to affect the confidentiality, integrity or availability of information without authorisation. For a company whose product is literally attack technique, "reason to know" is not a comfortable standard to be arguing about after the fact. It is another reason the buyer-vetting architecture in Copy Daybreak's architecture is a compliance artefact and not just a commercial one.
Reading the two rulebooks together, and alongside the target discipline in The terms of service bite first: attack trajectories against published CVEs, plus reasoning traces, malware analyses and detection rules, are on BIS's own stated reading very unlikely to be controlled as 4E001.c. Exposure concentrates in a narrow band — the command-and-control frameworks, implants and delivery tooling contractors build to generate the data, technology for developing that tooling, and anything zero-day or undisclosed. That is a strong argument for keeping the tooling and the corpus in separate product lines with separate classifications, which is also how The law is about to arrive would have you think about the company overall.
Is a corpus a "cyber-surveillance item"?
Probably not. Article 2(20) defines cyber-surveillance items as dual-use items "specially designed to enable the covert surveillance of natural persons by monitoring, extracting, collecting or analysing data from information and telecommunication systems." A dataset of attack trajectories is not specially designed to surveil anyone and does not monitor anybody [UNVERIFIED, but the textual reading is reasonably confident].
It matters because Article 5 is the catch-all that bites hardest: an authorisation is required for non-listed cyber-surveillance items where the exporter has been informed by the authority, or is aware from its own due diligence, that the items may be intended for "internal repression and/or the commission of serious violations of human rights and international humanitarian law." Exporters who become aware must notify. The Commission's Guidelines on the export of cyber-surveillance items under Article 5, issued 15 October 2024, set the expected standard: per-transaction assessment of misuse capability, examination of all parties, red flags such as marketing of covert features or evidence of prior repressive use, a human-rights impact assessment, component-level analysis, and possible product modification (Akin Gump summary; SIPRI commentary).
Article 2(9) is worth a second look too: "technical assistance" covers "instruction, advice, training, transmission of working knowledge or skills or consulting services, including by electronic means." A corpus produced specifically to teach a model sits conceptually close to that definition, even though technical-assistance controls are directed at controlled items.
What an EU-to-US shipment actually requires
Assembled, the realistic compliance package is unglamorous and mostly paperwork — which is the good news, because paperwork is cheap relative to the alternative.
- A written classification, counsel-reviewed, of the corpus and of any tooling produced alongside it, against Annex I 4A005/4D004/4E001, with a documented conclusion. Re-run per product line.
- A public-domain determination. Where trajectories derive from published CVEs and public PoCs, document that the underlying technology is "in the public domain" and that the company places no restriction on further dissemination of that underlying information.
- Article 5 screening per the October 2024 Guidelines for every buyer, with a notification pathway to the national authority if a red flag appears.
- End-user certificates and contractual no-re-export and no-onward-supply clauses — the same clauses the labs themselves impose downstream.
- Sanctions and denied-party screening on every contractor and buyer, against both EU and US lists.
- An Internal Compliance Programme to the Commission's recommended standard, with training and record-keeping.
- US-side confirmation of the buyer's own EAR obligations for re-export or deemed export, and whether any US-origin controlled technology flows back to EU contractors — which would make the company a re-exporter.
Step 2 contains the subtlest problem in the whole dossier. Gating the corpus for misuse reasons — the entire architecture of The corpus is the target — is a restriction on dissemination of the compilation. It does not un-publish the underlying CVE technology, and the argument that the compilation and the underlying technology are separable is almost certainly right. But it is exactly the point at which an export authority could disagree [UNVERIFIED], and it should be written down before someone asks, not after.
No BIS advisory opinion, no EU authority guidance, and no published enforcement action addresses AI training data as controlled technology. This is a genuinely novel classification question, not a settled one being ignored. A formal BIS classification request or advisory opinion is cheap relative to the risk and produces a document you can hand to a buyer's compliance team.
Equally: no exploit broker, red-team tooling vendor or AI data vendor publishes its export-control posture. The only visible traces of how the industry actually handles this are the 2015 mobilisation against the BIS proposed rule and the 2017 Wassenaar amendments — lobbying for exemptions rather than licensing. A market read from a trade-controls firm would be worth paying for.
What this means in practice
The export-control problem is not a wall, it is a discipline, and the discipline is mostly the same one that makes the product safe and insurable. Published CVEs only. Tooling classified separately from data. A buyer file for every counterparty with an end-user certificate and a human-rights screen in it. An ICP that exists before the first shipment rather than after the first question.
The one thing that genuinely cannot be fixed by discipline is the visibility problem. Physical export control works because a crate crosses a border and someone stamps a form. Here the export is an scp, and the only mechanism that will ever flag it is one the company builds for itself. That argues for making transfer a deliberate, logged, human-approved step in the product — which is also, conveniently, what The corpus is the target requires for entirely different reasons.
Next: Copy Daybreak's architecture, on who is permitted to receive any of this, and what the buyers already demand of themselves.