A server, a networking switch, or a rack of GPUs crossing a border in 2026 is rarely governed by one country’s rule. It is usually governed by several at once: a multilateral baseline most governments have agreed to, plus whatever additional controls the exporting country, the destination country, and sometimes a third country with a legal claim on the technology have layered on top. For data centre hardware specifically, and above all for the advanced chips that power AI infrastructure, this stack of overlapping regimes is not a minor compliance footnote.
It decides whether a deal can close, whether a tenant can be hosted, and whether a piece of equipment can move at all.
This guide sets out how that global system actually fits together: the multilateral arrangement that most national rules are built on, how the United States, the European Union, and the United Kingdom each go further than that baseline in their own way, and what a global data centre operator or hardware importer needs to check before assuming a shipment or a deployment is clear.
Why now: a US rule extending export controls to foreign affiliates of listed entities is suspended only until 10 November 2026. When it resumes, ownership and tenant links that are invisible today can bring a data centre operator into scope, even one based entirely outside the US. The time to map that exposure is before the clock runs out, not after.
Export Controls and Data Centre Hardware: At a Glance
- There is a global floor, not a single global rule: the Wassenaar Arrangement sets a baseline list of dual-use items that 42 participating states agree to control, but each country decides its own licensing and can go further unilaterally.
- The major economies all go further: the United States, the European Union, and the United Kingdom each maintain their own, larger set of controls on top of the multilateral baseline, and the three do not fully align.
- Advanced chips and data centre hardware are the current focus: semiconductor manufacturing equipment, advanced computing integrated circuits, and AI-capable GPUs are among the most actively controlled and most frequently updated categories across every major regime.
- A live deadline is approaching: a US rule extending export controls to foreign affiliates of listed entities is suspended until 10 November 2026, and data centre owners and operators are being advised to review their ownership and counterparty structures before the suspension lifts.
- Compliance is per-jurisdiction, not once: a global operator has to check the rules of the exporting country, the destination country, and sometimes a re-export or ownership link back to a third country, for every relevant shipment or hosting arrangement.
The Multilateral Floor: The Wassenaar Arrangement
Most national export control regimes for dual-use technology, including data centre hardware, trace back to a single multilateral agreement. The Wassenaar Arrangement, established in 1996 and now counting 42 participating states including the United States, the United Kingdom, most of the European Union, Japan, and South Korea, is the world’s primary multilateral arrangement for controlling conventional arms and dual-use goods and technologies. Member states collectively agree on a list of items, including a category covering semiconductors, semiconductor production equipment, and related electronics, and each then applies its own national export licensing to items on that list.
The key point about Wassenaar is that it is a floor, not a ceiling. Member states can impose stricter unilateral controls beyond the agreed list, which is exactly what the United States has done extensively. Wassenaar also currently has a structural weakness worth knowing.
Because decisions require consensus among all participating states, and Russia is a member, Russia has vetoed updates to the list since 2022, leaving the multilateral baseline unable to keep pace with fast-moving categories like advanced semiconductors and AI-capable chips. In practice, this has pushed the United States, the European Union, the United Kingdom, and other allies toward unilateral and coordinated controls that sit well outside what Wassenaar itself has agreed.
Where the Floor Stops: How the Major Regimes Go Further
On top of the Wassenaar floor, the world’s largest markets for data centre hardware each run their own, more extensive control regime. The three worth understanding in detail are the United States, the European Union, and the United Kingdom, since together they cover most of the origin points and destinations for advanced data centre hardware.
The United States: the Entity List and extraterritorial reach
The United States controls dual-use exports through the Export Administration Regulations, administered by the Bureau of Industry and Security. Beyond adopting the Wassenaar list, the US maintains its own Entity List naming organisations, mostly in China and Russia, that are restricted or prohibited from receiving controlled US-origin technology, and it has placed the most sensitive AI-capable GPUs under some of the strictest licensing conditions of any regime.
The US export control regime has extraterritorial reach. It extends beyond the shipment itself to cover foreign affiliates and intangible technology transfers. A rule extending these restrictions to foreign affiliates that are 50% or more owned by a listed entity is currently suspended, but only until 10 November 2026, and BIS has indicated it will continue evaluating the national security case for those affiliated entities. Data centre owners and operators, including those based entirely outside the US, are being advised to review their ownership and investment structures, and the structures of their counterparties and tenants, well before that suspension lifts.
This matters specifically for data centre operators because the concern extends beyond physical hardware: hosting GPU workloads for a tenant connected to a listed entity, even where no chip physically leaves the country, can raise US export compliance questions.
The European Union: one regulation, direct effect across member states
The European Union controls dual-use exports through a single instrument, Regulation (EU) 2021/821, which applies directly across every EU member state without needing separate national legislation. Its Annex I list of controlled items is reviewed and updated roughly once a year to reflect decisions taken under Wassenaar and the other multilateral regimes, most recently entering into force in November 2025 with new controls on semiconductors and advanced computing.
Exporters moving controlled dual-use items out of the EU need an export authorisation from the relevant national authority in the member state of export, so while the list itself is harmonised, the licensing process still runs through national bodies.
The United Kingdom: its own list, post-Brexit
Since leaving the EU regime, the United Kingdom has run its own Strategic Export Control Lists, compiled from seven separate pieces of international control legislation and administered by the Export Control Joint Unit. Anyone exporting or transferring controlled goods, software, or technology from the UK, including intangible technology transfers, needs a licence from the ECJU if their items appear on the consolidated list.
Even where they do not appear on the list, the ECJU can still invoke end-use controls where there is a specific concern. The UK list broadly tracks the EU and Wassenaar lists, since both draw on the same underlying multilateral regimes, but the two have diverged on specific items since the UK began setting its own list independently, so an item’s status cannot be assumed to be identical on both sides of the Channel.
The Export Control Stack: A Quick Reference
| Layer | What it is | Who it binds | Key controlled tech | End-use controls |
|---|---|---|---|---|
| Wassenaar Arrangement | Multilateral baseline dual-use list, agreed by consensus | 42 participating states, via each one’s national law | Semiconductors, production equipment, electronics | Set nationally by each member |
| United States (EAR / Entity List) | Wassenaar list plus extensive unilateral controls and named-entity restrictions | US-origin items, and some foreign affiliates of listed entities | Advanced AI GPUs, semiconductor tools, compute | Broad, including catch-all and affiliate rules |
| European Union (Regulation 2021/821) | A single harmonised dual-use list with direct effect, licensed nationally | Exports from any EU member state | Semiconductor equipment, advanced computing ICs | Yes, including a catch-all for unlisted items |
| United Kingdom (Strategic Export Control Lists) | An independent post-Brexit list drawing on the same multilateral sources | Exports and technology transfers from the UK | Dual-use electronics, computing, technology | Yes, ECJU end-use controls apply |
The practical reading of this table is that no single layer tells you the full picture. An item cleared under Wassenaar’s baseline list can still be restricted under a specific country’s unilateral controls, and a licence granted in one jurisdiction says nothing about whether the same item is controlled, or controlled differently, in another.
The Shift Most Operators Miss: You Can Trigger Controls Without Exporting Anything
Here is the part of the 2026 landscape that catches data centre operators off guard, and the reason export controls are no longer just a problem for whoever ships the box. The traditional model is simple: a chip crosses a border, and the exporter needs a licence. That model still holds, but it is no longer the whole picture. The controls increasingly follow the controlled capability, not just the physical hardware.
In practice, this means an operator can raise export compliance questions while every server stays exactly where it is. If you host AI workloads for a tenant that is connected to a restricted entity, the concern is that a controlled capability, advanced compute, is being made available to a party that is not supposed to have access to it, regardless of where the GPUs physically sit. Remote access to controlled compute, provided as a service, is being treated by regulators as something that can carry the same sensitivity as shipping the chip itself.
The consequence is concrete: a data centre operator is now expected to know who its tenants are and who ultimately owns or controls them, in the same way an exporter is expected to know its end customer. Renting rack space or compute to a counterparty you have not screened is no longer a purely commercial decision. It has become a compliance one. This is the single biggest change in how export controls reach the data centre sector, and it is the one least reflected in older guidance that still treats the topic as a shipping question.
In our experience, this is where otherwise careful operators are most exposed, because they have a mature process for physical shipments and no equivalent process for screening who sits on their compute.
Moving data centre hardware across borders and not sure which regimes apply? Carra Globe can check your shipment against the relevant export control lists for both the origin and destination country before it moves.
Book a free export control screening before 10 November 2026 →
Why This Matters Specifically for Data Centre Operators
Export controls have traditionally been thought of as a hardware-shipment problem: a chip crosses a border, and the exporter needs a licence. For data centre operators in 2026, the exposure is broader than that.
- Tenant and counterparty screening. Hosting GPU workloads for a tenant connected to a restricted entity can raise compliance questions even when no physical export occurs, because the concern is about who has access to the controlled capability, not only where the hardware sits.
- Ownership structure review. With the US affiliates rule suspended only until 10 November 2026, operators with cross-border ownership or investment structures are being advised to review those structures now rather than after the suspension lifts.
- Procurement across jurisdictions. A data centre buying hardware from one country for a facility in another has to check the export rules of the origin country and the import rules of the destination separately, since clearing one side does not clear the other.
- Reciprocal controls elsewhere in the world. Export controls are not only a Western instrument. China maintains its own export control law and has used it to restrict outbound shipments of materials critical to hardware manufacturing, which our separate guide to China’s rare earth export controls covers in detail.
Taken together, this means export control compliance for a data centre operator is no longer a one-time check at the point of import. It is an ongoing screening obligation that touches procurement, tenant onboarding, and corporate structure alike.
The Four-Point Export Control Check
The regimes are complex, but the questions you need to answer for any given shipment or hosting arrangement are not. Run these four in order. Any “unsure” is a signal to get the item and the parties formally checked before you commit, not after.
- Is the item controlled? Classify it first. Establish whether your hardware, software, or technology has a control list rating under the relevant regime. Advanced GPUs, semiconductor manufacturing equipment, and related electronics are the categories most likely to be listed, so start there. Classification is the foundation: everything else depends on it.
- Where is it going, and where is it from? Check the export rules of the origin country and the import and end-use rules of the destination separately. A single shipment can sit under the US, EU, or UK regime on the way out and a different set of rules on the way in, and clearing one side never clears the other.
- Who are all the parties, all the way up? Screen them. Screen the buyer, the consignee, the tenant, and their ultimate owners against the relevant restricted-party and entity lists. With the affiliates rule resuming on 10 November 2026, ownership links matter as much as the named entity itself.
- Is a capability being made available, even without a shipment? If you are hosting compute or providing remote access rather than shipping hardware, ask whether a controlled capability is reaching a party that should not have it. If so, the same screening applies as if you were exporting the chip.
Most compliant outcomes come from running these four early, while there is still time to apply for a licence or decline a counterparty. Most expensive ones come from running them after the goods have moved or the tenant is already onboarded.
How Carra Globe Helps
Navigating four or more overlapping regimes at once is exactly the kind of problem that benefits from a partner who works across borders rather than within just one.
Carra Globe acts as importer of record and exporter of record for data centre and IT hardware across 175+ countries, checking classification and licensing requirements against the relevant national export control lists before a shipment moves, not after it stalls. Our global trade compliance team tracks the Wassenaar, US, EU, and UK lists as they are updated, and our IT hardware and data centre trade compliance guide covers the import side of the same equipment in full. For operators with cross-border ownership or tenant structures, we can also help map the exposure ahead of the US affiliates rule’s 10 November 2026 deadline.
The control-regime details in this guide are drawn from the primary regulator sources linked throughout, the Wassenaar Arrangement, the US Bureau of Industry and Security, the EU’s official regulation text, and the UK government’s export control guidance, and reflect the position as of the date above. Because these lists change frequently, always confirm the current status of your specific items directly.
Frequently Asked Questions: Export Controls and Data Centre Hardware
What are export controls on data centre hardware?
Export controls are government restrictions on which countries or entities can receive certain hardware, software, or technology, applied because the item could have a military use as well as a civilian one.
For data centre hardware, this covers semiconductors, semiconductor manufacturing equipment, and advanced computing chips such as AI-capable GPUs.
What is the Wassenaar Arrangement?
The Wassenaar Arrangement is a multilateral agreement, signed in 1996, in which 42 participating states agree on a shared list of dual-use goods and technologies that each then controls under its own national law.
It sets a baseline, not a ceiling. Member states are free to impose stricter, unilateral controls beyond what Wassenaar itself has agreed.
Is there one global export control law?
No. The Wassenaar Arrangement provides a shared baseline list, but the United States, the European Union, the United Kingdom, and other countries each apply their own, often stricter, controls on top of it.
A shipment can be affected by several of these regimes at once, depending on its origin, destination, and the parties involved.
How does the EU Dual-Use Regulation work?
Regulation (EU) 2021/821 sets a single, harmonised list of controlled dual-use items that applies directly across every EU member state, updated roughly annually to reflect the latest multilateral decisions.
Exporters still apply for their licence through the national authority in the member state they are exporting from, even though the underlying list is common to the whole EU.
Do I need an export licence to move servers from the UK to Germany?
For most standard IT hardware, no. But it depends on whether the specific items are on the UK’s control list, and controlled dual-use items still need an ECJU licence even for a movement to Germany.
Standard servers are often not controlled, but advanced computing hardware can be. Classify the specific equipment against the UK list before assuming a transfer to an EU country is licence-free.
Can a data centre in Singapore be affected by US export controls?
Yes. US export controls can reach US-origin hardware and technology wherever it ends up, and can apply to dealings with restricted entities, so a data centre outside the US can still be in scope.
If the facility handles US-origin advanced hardware, or hosts or transacts with a restricted party, US rules can apply regardless of where the data centre is located.
What happens if I ship GPUs to a company 51% owned by a listed entity after November 2026?
Once the affiliates rule resumes, a company majority-owned by an Entity List company is expected to inherit that entity’s restrictions, so such a shipment would likely require a licence or be prohibited.
The rule’s final form is still being settled, so treat any counterparty with 50% or more listed-entity ownership as high-risk and seek a formal compliance check before shipping, rather than assuming the exact outcome.
How is the UK’s export control regime different from the EU’s?
Since leaving the EU regime, the UK maintains its own Strategic Export Control Lists, administered by the Export Control Joint Unit, drawing on the same multilateral sources but no longer identical to the EU list.
The two lists have diverged on specific items since the UK began setting its list independently, so status under one cannot be assumed for the other.
What is the US Entity List?
The Entity List is a US government list of organisations, mostly in China and Russia, that are restricted or prohibited from receiving certain US-origin technology without a specific licence.
It is maintained by the Bureau of Industry and Security and is one of the main tools the US uses to control the destination of sensitive hardware and technology.
What is the US affiliates rule and why does the November 2026 date matter?
It is a US rule extending export restrictions to foreign entities that are 50% or more owned by an Entity List company, currently suspended until 10 November 2026.
Data centre owners and operators with cross-border ownership or investment structures are being advised to review those structures before the suspension lifts, since BIS has indicated it will keep evaluating the underlying national security case.
Can hosting GPU workloads trigger export control concerns without a physical export?
Yes. Hosting AI workloads for a tenant connected to a restricted entity can raise export compliance questions even where no chip physically leaves the country, because the concern is about access to the controlled capability.
This is why data centre operators, not only hardware exporters, are increasingly expected to screen their tenants and counterparties.
Do export controls apply to software and technology, not just physical hardware?
Yes. Most major regimes, including the UK and EU lists, explicitly cover software and intangible technology transfers, not only physical goods.
Sending controlled technical data or software across a border, including electronically, can require the same licence as shipping a physical item.
How often do export control lists change?
Frequently. The EU list is typically updated about once a year, the UK list around twice a year, and the US list is amended on an ongoing basis as new entities and technologies are added.
An item’s control status should be rechecked periodically rather than assumed to be fixed, particularly for fast-moving categories like AI chips.
Which data centre hardware categories are most affected?
Advanced computing integrated circuits and GPUs, semiconductor manufacturing and testing equipment, and related electronic assemblies are the categories seeing the most frequent new controls across every major regime.
These are also the categories most likely to appear on a country’s most restrictive licensing tier, so they warrant the closest classification review.
Related Guides
- China’s rare earth export controls: how China uses its own export control law to restrict materials critical to hardware manufacturing.
- IT hardware and data centre trade compliance: the import side of moving the same equipment across borders.
- Importer of record services: how the legal importer function works when you have no local entity in a market.
Disclaimer: this guide is educational and does not constitute legal or export compliance advice. Export control regimes change frequently and interact in complex, jurisdiction-specific ways. Always confirm the current classification and licensing requirements for your specific goods and jurisdictions with a qualified export compliance advisor before shipping.