Summary
- David Peters (Assistant Secretary for Export Enforcement, Bureau of Industry and Security) announced that BIS is prioritizing data analytics and the Disruptive Technology Strike Force to block illicit technology transfers.
- Peters testified that the agency is shifting its enforcement posture to address nation-state actors using shell companies and transshipment hubs to bypass U.S. semiconductor export controls.
- Rep. Perry (R, PA-10) pressed Peters on why the U.S. allows exports to countries like China that refuse end-use checks, calling the current Entity List process a "whack-a-mole" game.
- Republicans advocated for a stricter presumption of denial for sensitive technologies, while Rep. Kamlager-Dove (D, CA-37) emphasized incorporating human rights criteria and supporting small business compliance resources.
- The Department of Commerce is finalizing a rule to close the "cloud computing" loophole that allows foreign adversaries to access high-end AI chips through U.S.-based infrastructure services.
Transcript
Opening Statements and Witness Testimony
[Gavel sounds.] The subcommittee will come to order. The purpose of this hearing is to examine the Department of Commerce's efforts to strengthen export control enforcement and protect our national security interests. I want to welcome our witness, Assistant Secretary David Peters, and thank him for being here today. Export controls are a critical tool in our national security toolkit. They allow us to prevent sensitive technologies from falling into the hands of our adversaries, particularly the Chinese Communist Party, Russia, and Iran. However, these controls are only as effective as their enforcement. We have seen reports of illicit procurement networks continuing to bypass our regulations to acquire high-end semiconductors and other dual-use technologies. Today, we want to hear about how the Bureau of Industry and Security is adapting its enforcement strategies to meet these evolving threats. I now recognize the ranking member, Ms. Kamlager-Dove, for her opening remarks.
Thank you, Mr. Chairman. And thank you, Assistant Secretary Peters, for your service and for appearing before us today. Strengthening our export control enforcement is not just about national security; it is about maintaining the integrity of the global trade system. We must ensure that our enforcement actions are targeted, effective, and coordinated with our international partners. I am particularly interested in hearing about the challenges BIS faces in monitoring global supply chains and how we can better support your mission through legislative action or increased resources. I look forward to your testimony.
Thank you. I now recognize the Honorable David Peters, Assistant Secretary of Commerce for Export Enforcement. Your full written statement will be made part of the record. Please keep your oral testimony to five minutes. You may begin.
Chairman Huizenga, Ranking Member Kamlager-Dove, and members of the subcommittee, thank you for the opportunity to testify today on the Department of Commerce's export enforcement mission. At the Bureau of Industry and Security, or BIS, our mission is to advance U.S. national security, foreign policy, and economic objectives by ensuring an effective export control and treaty compliance system. In recent years, the threat landscape has shifted dramatically. We are no longer just dealing with traditional proliferation; we are facing nation-state actors who are systematically attempting to acquire U.S. technology to modernize their militaries and suppress their citizens. To meet this challenge, we have significantly enhanced our enforcement posture. We have increased our use of administrative authorities, expanded our cooperation with the Department of Justice through the Disruptive Technology Strike Force, and deepened our engagement with international allies. We are also leveraging data analytics to identify suspicious patterns and preemptively block illegal shipments. Despite these efforts, the scale of the challenge is immense. Our adversaries are persistent and well-resourced. We remain committed to using every tool at our disposal to protect American innovation and security. I look forward to your questions.
Enforcement Strategies and Industry Outreach
Thank you, Mr. Secretary. I will now recognize myself for five minutes of questioning. Mr. Peters, you mentioned the Disruptive Technology Strike Force. Can you elaborate on how that partnership with DOJ has changed the speed of your investigations?
Certainly, Mr. Chairman. The Strike Force has been a game-changer. By co-locating BIS special agents with federal prosecutors in 14 different metropolitan areas, we have been able to move from lead generation to indictment much faster. It allows for real-time sharing of classified and unclassified information, which is essential when dealing with fast-moving procurement networks. We have already seen dozens of enforcement actions resulting from this collaboration, targeting everything from illicit electronics smuggling to the illegal transfer of software source code.
Thank you. I now recognize the ranking member for her questions.
Thank you. Assistant Secretary Peters, one of the concerns we often hear from industry is the complexity of the regulations. How is BIS working with the private sector to ensure they understand their compliance obligations without stifling legitimate trade?
That is a critical point, Congresswoman. Outreach is a core pillar of our enforcement strategy. We conduct hundreds of company visits every year to educate firms on 'red flags' of illicit procurement. We also provide detailed guidance on our website and through our seminars. Our goal is to make the private sector our first line of defense. When companies have robust internal compliance programs, they are much more likely to catch and report suspicious inquiries before a violation occurs.
Thank you. I yield back.
Entity List Evasion and International Cooperation
The chair recognizes the gentleman from Pennsylvania, Mr. Perry.
Thank you, Mr. Chairman. Mr. Peters, let's talk about the Entity List. We see companies like Huawei and others on there, but we also see reports that they are still managing to get U.S. chips through third-party distributors in places like Hong Kong or the UAE. Why is it so hard to shut down these middleman networks, and what more do you need from us to stop it?
Congressman, you've identified one of our most significant challenges. Transshipment through third countries is the primary method used to evade our controls. These networks are often composed of shell companies that appear and disappear overnight. To combat this, we have increased our 'end-use checks' in high-risk jurisdictions. We have also implemented the Foreign Direct Product Rule, which gives us jurisdiction over items made abroad using U.S. software or technology. However, the sheer volume of global trade makes 100 percent coverage difficult. We are working to expand our 'Unverified List' to put companies on notice when we cannot complete an end-use check, which often serves as a precursor to being added to the Entity List.
But isn't it true that the license approval rate for some of these entities is still quite high? It seems like we put them on the list and then just grant waivers anyway.
The licensing process is rigorous and involves a multi-agency review, including the Departments of State, Defense, and Energy. While some licenses are granted for less sensitive items that don't pose a national security risk, the overall trend has been toward much stricter denials, especially for advanced computing and semiconductor manufacturing equipment destined for the PRC.
The chair recognizes the gentleman from California, Mr. Bera.
Thank you, Mr. Chairman. Mr. Peters, I want to touch on international cooperation. Our controls are much more effective when our allies, like the Netherlands and Japan, implement similar restrictions. Can you update us on the progress of multilateralizing some of our recent unilateral controls on advanced semiconductors?
Thank you, Congressman. Diplomacy is essential to our success. We have had very productive discussions with our partners in the G7 and beyond. As you noted, Japan and the Netherlands have taken significant steps to align their controls with ours regarding semiconductor manufacturing equipment. We are also working through the Wassenaar Arrangement and other multilateral regimes, though those can be slower due to the requirement for consensus. Our strategy is to build 'plurilateral' coalitions of like-minded countries that can move more quickly to address emerging threats.
And are you seeing any pushback from allies who are concerned about the economic impact on their own industries?
There are always economic considerations, but there is a growing recognition among our allies that the security risks posed by the PRC's military-civil fusion strategy outweigh the short-term commercial gains. We work very closely with them to ensure that our controls are as narrow and targeted as possible to minimize unintended economic consequences while maximizing the security impact.
The chair recognizes the gentleman from Texas, Mr. Self.
Thank you, Mr. Chairman. Mr. Peters, I'm concerned about the 'deemed exports' issue—the transfer of technology to foreign nationals within the United States, particularly in our universities and research labs. How is BIS monitoring these transfers, and do you have enough boots on the ground to actually enforce these rules in an academic setting?
...and the enforcement actions that we've taken. We are working very closely with our allies in the G7 and beyond to ensure that our export control regimes are harmonized and that we are closing any potential loopholes that could be exploited by our adversaries.
Thank you, Mr. Peters. I now recognize the gentleman from Pennsylvania, Mr. Perry, for five minutes of questioning.
Thank you, Mr. Chairman. Mr. Peters, thank you for being here. I want to talk about the Entity List. Specifically, we've seen reports that certain Chinese companies that are on the list are still able to acquire sensitive U.S. technology through subsidiaries or third-party distributors in countries like the UAE or Malaysia. What is BIS doing to map these corporate networks and ensure that being on the Entity List isn't just a speed bump for these firms? Because right now, it feels like we're playing a game of whack-a-mole where we put one entity on the list and three more pop up under different names the next day. How are we using data analytics or intelligence community resources to get ahead of this curve rather than just reacting to it after the technology has already left our shores?
Congressman, you've hit on one of our most significant challenges. The 'whack-a-mole' analogy is one we often use internally. To address this, we have significantly expanded our regulatory reach. For example, we've implemented the Foreign Direct Product Rule, which allows us to control items made outside the United States if they are the product of certain U.S. technology or software. Regarding the corporate mapping, we are increasingly using advanced data analytics to identify shell companies and front organizations. We also work very closely with our colleagues in the intelligence community to identify these networks before the transactions occur. We've also increased our 'Verified End-User' program requirements and are conducting more post-shipment verifications, although I will admit that in certain jurisdictions, our ability to conduct those checks is limited by the host government.
When you say 'limited by the host government,' I assume you're referring to the PRC. If they don't let us verify where the tech is going, why are we letting it go there at all? Shouldn't there be a presumption of denial for any dual-use technology going to a country that refuses to allow end-use checks? It seems to me we're prioritizing commerce over national security in those instances.
We have actually moved toward a policy of 'is it verifiable?' If we cannot verify the end use, that is a significant factor in our licensing decisions. In fact, for many of the most sensitive technologies, particularly in the semiconductor and AI space, we have moved to a presumption of denial for the PRC. We are constantly evaluating that balance.
Human Rights, Maritime, and Technology Loopholes
The gentleman's time has expired. I now recognize the Ranking Member, Ms. Kamlager-Dove, for five minutes.
Thank you, Mr. Chairman. Mr. Peters, I want to pivot slightly to the human rights aspect of export controls. We know that surveillance technology is being used by authoritarian regimes to crack down on dissent and target marginalized communities. How is BIS incorporating human rights considerations into the licensing process, and are we coordinating with our democratic allies to ensure that we aren't just ceding the market for these surveillance tools to companies in countries that don't share our values?
Thank you for that question. Human rights are now a formal part of our review process. In 2021, we published a final rule that explicitly identifies human rights as a basis for denying a license. We are also leading an international effort through the Export Controls and Human Rights Initiative, which was launched at the Summit for Democracy. This initiative aims to establish a code of conduct for governments to prevent the proliferation of software and other technologies used to enable serious human rights abuses. We want to ensure that U.S. innovation is not being used to facilitate repression.
I appreciate that. I'm also concerned about the resources available to your department. You're tasked with monitoring a massive global supply chain with a relatively small staff. If Congress were to provide additional funding, where would it be most effectively deployed? Is it more boots on the ground for inspections, or more software and data scientists for the analytics you mentioned earlier?
It's really both, but if I had to prioritize, the data analytics piece is a force multiplier. Having the ability to screen millions of transactions in real-time to flag suspicious patterns allows our 'boots on the ground' to be much more targeted and effective. That said, we also need more enforcement agents stationed overseas in key transshipment hubs to conduct those physical inspections and build relationships with local customs authorities.
The gentlewoman yields. I now recognize the gentleman from Texas, Mr. Self.
Thank you, Mr. Chairman. Mr. Peters, I want to follow up on the transshipment issue. We see a lot of 'dark fleet' activity and ship-to-ship transfers to bypass sanctions and export controls, particularly regarding oil and sensitive components. How much visibility does BIS actually have into these maritime activities, and are you working with the Treasury Department's OFAC to coordinate enforcement against the shipping companies and insurers that facilitate this?
We work very closely with OFAC and the Department of Justice through the Disruptive Technology Strike Force. Maritime domain awareness is a key part of our enforcement strategy. We use satellite imagery and AIS tracking data to monitor suspicious vessel movements. When we identify a vessel involved in illicit transfers of controlled items, we can add that vessel or its owner to our Entity List, which effectively cuts them off from the U.S. financial system and U.S. goods. It is a constant battle of monitoring and response.
Is the current penalty structure sufficient to deter these large international shipping conglomerates? If the fine is just a fraction of the profit they make from the illicit trade, they'll just treat it as a cost of doing business. Do we need to increase the statutory maximums for these violations?
We have recently increased our administrative penalties, and we are working with Congress to look at the statutory limits under ECRA. But more than just the fines, the 'reputational' hit and the loss of access to the U.S. market are often the most significant deterrents for major global firms. No legitimate bank wants to finance a company that is on a U.S. restricted list.
I now recognize the gentleman from California, Mr. Bera.
Thank you, Mr. Chairman. Mr. Peters, I'm interested in the 'deemed exports' issue—the transfer of sensitive knowledge to foreign nationals within the United States, particularly in university research settings. How do we protect our intellectual property and sensitive research without stifling the open academic environment that makes the U.S. a leader in innovation? It's a delicate balance.
It is indeed a delicate balance, Congressman. We engage extensively with academic institutions through our outreach programs. We provide guidance on how to identify research that falls under the Export Administration Regulations. We aren't trying to stop fundamental research, which is generally exempt, but we are focused on applied research in sensitive areas like quantum computing or advanced biotechnology. We encourage universities to have robust internal compliance programs and to be vigilant about who has access to controlled labs and data.
Are you seeing an increase in voluntary disclosures from universities, or are most of these cases coming from your own investigations?
We have seen a significant increase in voluntary self-disclosures across the board, including from the academic sector. We've made it clear that a timely and complete self-disclosure is a major mitigating factor in any enforcement action. It shows a commitment to compliance, which we want to encourage.
I now recognize the gentleman from Tennessee, Mr. Burchett.
Thank you, Chairman. Mr. Peters, let's talk about the 'cloud computing' loophole. Right now, a foreign entity can't buy a high-end AI chip, but they can just rent time on a U.S.-based cloud server that uses those same chips. What are we doing to close that? It seems like a pretty big back door to me.
You're correct, that is a concern we are actively addressing. We recently issued a notice of proposed rulemaking that would require U.S. cloud service providers to verify the identity of their foreign users and report when those users are training large AI models that could be used for malicious cyber activity. We want to ensure that 'Infrastructure as a Service' isn't being used to circumvent our hardware controls.
When will that rule be finalized? Because every day we wait is another day our adversaries are using our own tech to train their models.
We are reviewing the public comments now and aim to move to a final rule as quickly as the administrative process allows. It is a high priority for the Secretary and the Bureau.
I now recognize the gentleman from New York, Mr. Latimer.
Thank you, Mr. Chairman. Mr. Peters, I want to ask about the impact of these controls on our small and medium-sized businesses. Large corporations have entire departments dedicated to compliance, but a small tech startup might not even know they're violating a regulation until it's too late. What resources are available to help these smaller players navigate this incredibly complex landscape?
That's a great point. We have a dedicated Office of Exporter Services that conducts seminars and webinars specifically for small businesses. We also have counselors available to answer specific questions about classification and licensing. We want to make compliance as straightforward as possible so that small businesses can compete globally without inadvertently running afoul of the law. We also have a 'SNAP-R' online system for license applications that is designed to be user-friendly.
Is there a way to fast-track applications for smaller companies or for technologies that are clearly low-risk?
We do have 'License Exceptions' for certain low-risk items and destinations. If a transaction meets the criteria for an exception, no formal license application is required, which significantly reduces the burden. We are constantly reviewing those exceptions to ensure they reflect the current threat environment.
Thank you. We will now take a brief five-minute recess before we continue with the remaining members. The committee stands in recess.
...and that is why we are so focused on the disruptive technology strike force. We are looking at those items that are going to be used for the next generation of weapons, and we are making sure that we are using every tool in our toolbox to keep them out of the hands of our adversaries.
I thank the gentleman. My time has expired. I yield back.
Closing Remarks
The gentleman yields back. I now recognize the Ranking Member, Ms. Kamlager-Dove, for any closing remarks she may have.
Thank you, Mr. Chairman. And thank you, Assistant Secretary Peters, for your testimony today and for your service. It is clear from our discussion that the Bureau of Industry and Security plays a critical role in our national security, particularly as we face increasingly complex threats from adversaries like China and Russia. I appreciate your insights into how BIS is adapting its enforcement strategies, leveraging data analytics, and strengthening partnerships with both domestic and international allies. It is vital that we continue to provide BIS with the resources and authorities it needs to effectively monitor and control the export of sensitive technologies. I also want to emphasize the importance of maintaining a balance between protecting our national security and ensuring that our export control policies do not unduly burden legitimate American businesses. We must remain vigilant and proactive in our efforts to stay ahead of those who seek to undermine our interests. I look forward to continuing our work together on these important issues. And with that, Mr. Chairman, I yield back.
The gentlelady yields back. I want to thank Assistant Secretary Peters for being here today. This has been a very productive hearing. The testimony and the answers to the questions have provided us with a better understanding of the challenges and opportunities facing the Bureau of Industry and Security. It is clear that export control enforcement is a dynamic and evolving field, and we must ensure that our policies and practices keep pace with the rapid technological changes and the shifting geopolitical landscape. We have heard about the importance of international cooperation, the need for robust enforcement mechanisms, and the value of engaging with the private sector. As we move forward, this subcommittee will continue to monitor these issues closely and work to ensure that our export control system remains a powerful tool for protecting our national security and promoting our economic interests. I also want to thank my colleagues for their participation and their thoughtful questions. Pursuant to committee rules, all members may have five days to submit statements and questions for the record, subject to the length limitations in the rules. Without objection, the subcommittee stands adjourned. [Gavel sounds.]
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



