
The $36M Penalty: How "Deemed Exports" Are Triggering ITAR's Harshest Fines
The Directorate of Defense Trade Controls (DDTC) just leveled a historic $36 million civil penalty against GE Aerospace. The focal point? Unauthorized exports of technical data. Here is why the front desk is your greatest vulnerability.
For defense contractors, the concept of a physical export is universally understood: you do not ship controlled hardware to restricted nations without a license. But in April 2026, the U.S. State Department’s DDTC issued a massive $36 million civil penalty to GE Aerospace, highlighting a much more insidious threat: unauthorized exports of technical data.
The Core Allegation
The settlement resolved 116 alleged violations of the Arms Export Control Act (AECA) and the ITAR, centering heavily on the unauthorized transfer of technical data to foreign nationals, including those from the PRC. Under the ITAR, "export" encompasses not just physical shipment, but revealing technical data to a foreign person within the United States—a concept known as a deemed export.
The Front Desk Vulnerability
How does an unauthorized export of technical data actually happen on American soil? In many cases, it walks right through the front door.
Defense contractors frequently host visitors: suppliers, auditors, maintenance technicians, and prospective clients. If your organization relies on paper visitor logs, badge-on-trust systems, or receptionist intuition, you are exposing your operation to extreme ITAR risk. A foreign national walking unescorted through a facility where USML-controlled blueprints are visible on screens, or where regulated hardware is being tested, can be an unauthorized export under the ITAR the moment they see the data.
The Legacy Approach
- ✗Self-reported citizenship on paper logs
- ✗Manual screening against DDTC debarred lists
- ✗Reliance on physical badges without escort enforcement
The Modern Defense Standard
- ✓Automated ID capture and citizenship recording
- ✓Screening against OFAC SDN and SSI, BIS, UN, EU, and UK lists at check-in
- ✓Recorded acknowledgments of NDA and TCP terms
The Audit Trail Is Your Evidence
When DDTC reviews an alleged violation, your own records are what show how access was controlled. If you cannot produce a timestamped record of every visitor who entered your facility, their citizenship status, their screening result, and the U.S. person who escorted them, your compliance program is built on sand.
A $36 million settlement is a stark reminder that regulatory bodies are not slowing down enforcement. They are looking for systemic weaknesses in how defense contractors protect their most valuable asset: data.
SecurePoint USA is built for the zero-margin-of-error reality of modern defense compliance. It screens visitors at check-in, can require signed agreements such as NDAs, and keeps a hash-chained audit log, so the front desk produces evidence instead of gaps.
Is Your Facility Audit-Ready?
- ITAR/EAR and CMMC L2 visitor checklist
- What auditors and primes look for
- Audit-ready evidence pack self test
Or get it sent to your inbox


