MICKAI®ArticlesUK Export Controls and Cloud AI: …
Article · 31 July 2026

UK Export Controls and Cloud AI: The Intangible Transfer Wall

Uploading controlled technical data to a cloud AI raises a licensable intangible transfer question under UK export control law, and sovereign on premise review removes it.

Author
Micky Irons
Published
31 July 2026
Follow Micky Irons
LinkedInX
sovereign-aiuk-export-controlsintangible-technology-transferdefence-manufacturingair-gapped-ai
UK Export Controls and Cloud AI: The Intangible Transfer Wall

Sending controlled technical data to a cloud AI service raises a licensable transfer question under UK export control law, and the defensible answer for British defence and dual use manufacturers is to keep AI review inside their own estate. The Export Control Order 2008 and the UK strategic export control lists restrict the transfer of controlled technology, including intangible transfers by electronic means, with licensing administered by the Export Control Joint Unit (ECJU). A cloud AI has to receive and process your data to work on it, so before anyone debates model quality, your export control officer must answer a harder question first: where does this data go, and who could touch it on the way?

Does UK export control law really apply to uploading data to a cloud AI?

Yes, because UK strategic export controls apply to technology as well as goods, and to electronic transfer as well as physical shipment. Controlled technology includes information needed for the development, production or use of items on the strategic export control lists, and transferring it by electronic means from the UK can require a licence just as shipping hardware can. Uploading a technical data package to a service whose servers, administrators or support engineers sit outside the UK is exactly the scenario that guidance on intangible transfers was written for. The question is not whether the vendor seems trustworthy, but whether the transfer itself is licensable, and that must be answered before the upload happens, not after.

What is an intangible technology transfer and why does it matter for AI?

An intangible technology transfer is the movement of controlled technology by non physical means, such as email, file upload, remote access or a shared drive, and every cloud AI workflow is built on exactly those movements. The United States frames this through its deemed export rules, where release of technical data to a foreign person counts as an export to that person's country. The UK framing rests on transfer and destination rather than nationality, but the practical wall is the same. Once controlled data leaves hardware you own, you can no longer demonstrate where it is processed, which jurisdictions its administrators sit in, or what copies exist. An export control officer cannot wave that through, and a serious one will not try.

Is this only a problem for defence primes?

No, the same wall stands in front of any business holding items or technology on the UK strategic export control lists, and the dual use list reaches further than most boards expect. Aerospace component makers, marine and subsea engineering firms, advanced materials producers and electronics businesses can all hold controlled technology without a single defence contract, because dual use controls follow the capability of the item, not the customer. Breaching UK export controls is a criminal matter enforced by HMRC, with penalties that can include imprisonment, and the compliance duty stays with the exporter, not with the software vendor whose service the data went through. That is why the processing location of an AI system is a board question, not an IT preference.

How does sovereign, on premise AI answer the export control question?

It answers the question by removing the transfer. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped, so controlled technical data is never uploaded anywhere. Our document review capability reads technical data packages, cross references certificates and licences against the records behind them, drafts the routine paperwork, and holds anomalies for a person to decide. Every action is sealed to the Open Audit Record before it runs, cryptographically signed, post quantum secure, tamper evident and verifiable offline, so an export control officer can show exactly what was reviewed, what was proposed and who cleared it. Consequential actions wait for a person's clearance. None of it requires trust in us, because the evidence is checkable on your own machines without any network connection.

An export control officer's job is to be able to say where controlled technology went and prove it. A cloud AI makes that answer harder. A sovereign system on your own hardware makes it a one line answer with evidence attached.

Mickai

What should our export control officer ask any AI vendor?

Ask questions that force the transfer issue into the open, because a vendor who cannot answer them in writing has already answered them.

  • Where, physically and jurisdictionally, is our data processed, and can you prove no copy leaves our estate?
  • Which of your staff, contractors or subprocessors could access our data, and from which countries?
  • Can the system run fully offline, air gapped, with no telemetry or call home of any kind?
  • What record exists of every action the system takes, and can we verify it offline, years later, without you?
  • Does the system execute consequential actions autonomously, or does it wait for a named person's clearance?
  • Will you state in writing that your architecture creates no licensable transfer of our controlled technology?

Where is this heading for British exporters?

Towards a settled expectation that AI working on controlled technology lives inside the accreditation boundary, the same way classified networks and secure rooms already do. Export control regimes tighten as technology outruns licensing categories, and intangible transfer questions will multiply as more engineering work runs through AI systems. The exporters who move fastest will be the ones who never created the question in the first place, because their review systems, evidence and audit records all live on hardware they own. That is the deployment shape we build for, and where we think the whole regulated economy ends up.

Frequently asked questions

Does uploading controlled technology to a cloud service count as an export?

It can. UK strategic export controls cover intangible transfers of controlled technology by electronic means, and moving data to servers or personnel outside the UK may be licensable. Whether a specific upload needs a licence depends on the technology, the destination and the licence coverage in place, a determination for your export control officer with the ECJU, not for an AI vendor.

What is the UK equivalent of the American deemed export rule?

The UK does not use the deemed export concept directly. Its controls rest on the transfer of controlled technology from the UK, including by electronic means, rather than the nationality of the recipient. The practical effect for cloud services is similar, because data processed or accessible abroad raises the same licensing questions.

Do open general export licences cover cloud AI processing?

Some open general export licences permit certain technology transfers under strict conditions, but whether any covers routing controlled data through a third party AI service is a case by case judgement. Many export control officers conclude the cleanest position is not to create the transfer at all, keeping processing on hardware the organisation owns.

Can we use AI on controlled technical data at all?

Yes, on infrastructure you own and control. Running AI review on premise and air gapped means the data never moves, so no transfer question arises from the processing itself. That is the deployment model Mickai is built for, with every review sealed to a tamper evident audit record a regulator can verify offline.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System (a SIOS) that runs entirely on the customer's own hardware, on premise and air gapped, so sensitive data never leaves the building. Every consequential action is sealed to the Open Audit Record, a cryptographically signed, post quantum, tamper evident record that is verifiable offline and sealed before the action runs. The system spans 87 studios, with ten production ready at launch and 77 in development, and it is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/uk-strategic-export-controls-beyond-itar. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles