Welcoming Our New (Compliance) AI Overlords
The AI future is here. For the past few years, I’ve been telling anyone who will listen that AI is going to soon impact all professions (even those...
I’ve previously written about why classification is such an important part of trade compliance and how teams can set themselves up for success. But trade compliance teams know that getting trade classifications right is no easy task. Why is it so challenging? There are many reasons, and I’m exploring them in this three-part series:
Each of these challenges compounds the others, creating a perfect storm that makes classification one of the most demanding tasks in trade compliance. At Trade Compliance Workbench, we’re addressing each of these challenges to allow teams to deliver better classification results faster and with more accuracy.
Today, let’s start with the foundation: the sheer volume of information teams must wrangle.
We’ve all seen them: dog-eared, printed binders full of regulations and lists; monitors with sticky notes all along the borders; carefully highlighted and organized PDFs; cheat sheets of commonly used classifications; decision trees. The list goes on and each team has their own favorites.
These tools are responses to a problem trade compliance teams have long wrestled with: there is a LOT of information – both about the item to be classified and the regulations and regulatory lists involved – that must be collected, sifted through, reviewed, and considered to properly classify an item.
Today, I’m going to explore this problem area a little further, breaking it into two core challenges: the complexity and volume of the regulatory lists themselves, and the extensive information-gathering required before you can even begin classification.
Each of the key US export control and import regulations have their own complex set of regulations and lists:
Side note: We’re setting aside NRC regulations, Schedule B classifications, and non-US regimes for now—each adds complexity worth its own discussion.
Last year, Felice Laird provided a useful “Compliance Complexity Pyramid” as a way to think about the difficulty of classifying under the different regimes (in the context of using AI for classifications):
(Felice also started an excellent group, “AI for Trade Compliance,” that you should consider joining.)
This categorization feels intuitively true-but is it? Let’s dive in!
Even without exploring all the rabbit holes we discussed above, the classification lists themselves are large and their sheer volume makes the information difficult to navigate and ingest. Here are some numbers from the key lists:
ITAR USML:
EAR CCL:
HTS (without Chapters 98 & 99):
HTS+ (including Chapters 98 & 99):
As you can see, the lists are large and the HTS is larger than either the EAR or the ITAR – or both put together. There are a LOT of HTS classifications to choose from. And this doesn’t even account for the dynamic, ever-changing nature of these lists, which we’ll explore in Part 3.
But raw size doesn’t tell the whole story. The graph of internal relationships between different regulatory nodes (cross-references, use of defined terms, dependencies) within each list is equally significant:
ITAR USML: 3,900+ relationships
EAR CCL: 27,000+ relationships
HTS: 31,000+ relationships
HTS+: 57,000+ relationships
And that’s on the low end! Many more relationships can be teased out to build richer knowledge graphs.
Let’s also normalize our relationship data by dividing relationships by the number of classifications—we’ll call this “density,” a measure of interconnectedness and complexity. This isn’t a precise scientific measurement, but it provides a useful metric for understanding relative complexity of each classification set: the higher the number, the more complex a list is to navigate and understand:
ITAR USML: ~3.5
EAR CCL: ~6.75
HTS: ~1.24
HTS+: ~1.96
The export lists are significantly denser than the HTS, and the CCL is the densest of them all (around 5X denser than the HTS!). It’s harder to classify under the EAR precisely because it requires constant pausing and thinking, jumping between categories, ECCN, notes and definitions, and constant “context resolution.” Not to mention the many rabbit holes that can quickly disorient you.
Thankfully, the U.S. government provides robust tools for the HTS. The USITC HTS website and CROSS offer searchable databases for classification research. Most importantly, the HTS is available in a structured format that makes it easier for systems (including TCW) to process and use for accurate classification.
The picture for export classifications is less encouraging. The U.S. government-provided tools for export classifications haven’t been as robust as those for the HTS. Neither the USML nor the CCL are available as structured data, and the tools provided aren’t as helpful. The state of the art for most teams has been manual approaches – cheat sheets, “Ctrl+F” searches, and team-specific tools that vary widely in effectiveness.
This is a problem we’ve tackled head-on at TCW. We’ve done the painstaking work of structuring the classification lists, deriving knowledge and relationship graphs, and developing algorithms to navigate this complexity. TCW helps teams quickly identify relevant import and export classifications for even the most challenging items and scenarios – with full explainability, traceability, and auditability.
Understanding the regulatory lists is only half the battle. Before even beginning the classification review process, classifiers must collect extensive information from multiple sources.
The starting point is gathering comprehensive technical details about the item being classified. This can include:
When classifying technology or technical data related to a physical item, the documentation requirements can multiply. Classifiers usually understand (or determine!) the appropriate classification of the associated hardware item itself before attempting to classify related technology / technical data.
Classification isn’t done in a vacuum. A classifier must research their company’s history of treating the item and other relevant precedents:
This historical research serves multiple purposes: ensuring consistency across the compliance program, learning from precedents, and avoiding taking contradicting positions.
Gathering all this information isn’t a solo endeavor. It requires coordination across multiple departments – product, engineering, sales, procurement, legal – and potentially with external parties. If the item isn’t of your own company’s design – and many times it isn’t – the classifier will need information from the design authority (could be the suppliers, customers, or some other OEM), including third-party classifications (which must still be verified), detailed technical specifications, and potential collection of the other information identified above.
Securing this information often requires careful relationship management and may involve long lead times. Each source may have different response times, different levels of understanding about what information is needed, different abilities to share relevant information, and different priorities. The compliance professional becomes a project manager, chasing down information, following up on requests, and assembling pieces from various sources into a coherent picture.
Before a compliance professional can even begin the analytical work of classification, they’re already managing a complex information-gathering operation across multiple systems, departments, and organizations. This front-end work is time-consuming and easy to underestimate, but it’s essential to getting the classification right.
TCW helps compliance teams gather relevant information quickly and smartly from existing documents such as data sheets, BOMs, prior classifications and more. TCW also provides a large searchable database of publicly-available classifications (both from industry and the USG) to help compliance teams gather additional contextual data, and standard forms and workflows for gathering additional information, both internally and externally.
In Part 1, we explored the information overload that trade compliance teams, especially those performing classifications, face – the voluminous lists, complex regulations, and extensive information-gathering required before classification can even begin. Today, I’m tackling another difficult aspect of classification: the nature of work itself. Over the years, I’ve repeatedly heard that classification is an art as much as it is a science. Let’s unpack why classification demands both engineering precision and interpretive judgment, and why that combination makes it uniquely challenging.
Here’s the first challenge: very few (if any?) academic programs teach trade compliance, much less classification. It’s a skill that’s learned on the job and requires training, time, and iterations to master. Most compliance professionals learn on the job, through mentorship, professional development programs, and years of accumulated practice.
But classifiers need even more. Beyond general trade compliance knowledge, they must master the mechanics of classification itself – the order of review, the General Rules of Interpretation (for HTS), the “specially designed” analysis (for ITAR and EAR), and the various rabbit holes unique to each regime.
And here’s where it gets really demanding: classifiers must usually also be product or engineering experts, or at least be able to quickly become conversant in highly technical domains. Good classifiers don’t just need trade compliance training – they often need engineering backgrounds too.
Consider what a classifier regularly encounters: data sheets full of technical specifications, a byzantine maze of potential classifications, lots of formulae, and a sea of technical acronyms that would give anyone SAD (that’s Severe Acronym Disorder).
Take advanced computing controls as an example. Classifying high-performance computers requires an understanding of how to calculate APP (Adjusted Peak Performance), measured in Weighted TeraFLOPS. The formula requires the determination of the peak 64-bit FPO (floating point operations) performed per cycle, processor frequency, and weighting factors that differ based on processor architecture.
Or consider the AI chip controls under ECCN 3A090 / 4A090. Classification depends on calculating the TPP (Total Processing Performance), which in turn requires an understanding of MacTOPS (the theoretical peak number of Tera operations pers second for multiply-accumulate computation). The related concept of Performance Density requires understanding non-planar transistor architectures, die area calculations, and how to handle multi-chiplet designs.
These aren’t isolated examples. Classifying quantum computing, encryption, composites, thermal imaging, cybersecurity items, and virtually every other category of controlled items in the CCL requires more than a surface-level understanding of both the classification AND the product and engineering involved.
The result is that effective classification teams often include – or need to have ready access to – engineers, product managers, and technical specialists. The compliance professional becomes a translator, bridging the gap between technical reality and regulatory language.
If classification were purely mechanical (i.e., a deterministic process where inputs always produce the same outputs) it would be far easier to systematize and automate. Here’s a reality that sometimes surprises people new to the field: there may be one or more classifications that could be applicable, depending on how the item being classified is conceptualized.
Is this item better understood as a component of a larger system, or as a standalone product? Is its primary function the feature that makes it technically sophisticated, or the mundane purpose it ultimately serves? Is it “specially designed” for a controlled end-use, or is that just one of many applications?
These aren’t trick questions with hidden right answers. They’re genuine interpretive challenges where experienced professionals can and often do reach different conclusions in good faith.
Consider the “specially designed” standard itself. The definition operates on a “catch and release” framework: paragraph (a) may “catch” an item as specially designed, but paragraph (b) may then “release” it from that designation. Easy enough, but I’ve personally seen spirited disagreement on whether a (b)(3) same function/form/fit release applied (what does “same” mean anyway?) or whether designers and engineers years ago (long since retired or left the company) had “knowledge” about the intended use or purpose. Reasonable minds could and did differ, with both presenting reasoned and defensible positions. One could, of course, get a CJ or CCATS determination to settle such issues but that is usually process, cost, and time prohibitive.
Classification also requires careful attention to catch-all controls, for example “n.e.s.” (not elsewhere specified) provisions and “other” categories that can ensnare items that don’t fit neatly into specific classifications. This is especially true for import classifications under the HTS. With over 29,000 potential classifications to choose from (including Chapters 98 and 99), there are many “other” rabbit holes to explore. When an item doesn’t squarely fit a specific provision, the classifier must navigate through residual categories, weighing which “other” best captures the item’s essential character.
This interpretive dimension is what makes classification genuinely difficult to reduce to simple decision trees (believe me, I have tried). Two classifiers looking at the same item might reach different conclusions, not because one is wrong, but because they’re conceptualizing the item differently. Both approaches might be defensible. The “right” answer often depends on factors that resist easy quantification: how similar items have been treated historically, what the regulatory intent appears to be, how the item will actually be used, and how the company wants to position itself from a compliance risk perspective. It requires judgment informed by experience, precedent, and a deep understanding of both the item and the regulatory intent, not to mention organizational history, risk preferences, and business impact.
This is where classification becomes genuinely artful. The best classifiers develop an intuition built over years of practice for how to navigate ambiguity, when to seek formal government guidance, and how to document their reasoning in ways that will hold up to scrutiny.
In Part 1, we explored the information overload that classification demands: the voluminous lists, complex regulations, and extensive information-gathering required before classification can even begin. In Part 2, we examined the dual nature of classification work itself: requiring both engineering precision and interpretive artistry. Today, I’m tackling the final dimension that makes classification uniquely demanding: the relentless pressure under which this work must be performed.
Classification doesn’t happen in a quiet library with unlimited time. It happens in the crucible of business operations, with real deadlines, real stakes, and real consequences. Let’s unpack the forces that turn classification into a pressure cooker.
The first pressure is sheer volume. Whether your team is tackling a lookback project on legacy products, reviewing reams of documentation that need to be delivered yesterday, managing a flood of new SKUs from product development, or onboarding items from a new supplier or acquisition, there is always pressure to move faster and achieve higher throughput.
A Fortune 100 manufacturer might introduce thousands of new part numbers quarterly. A smaller distributor might suddenly need to classify an entire product line from a new overseas supplier. In both cases, the classification queue grows faster than teams can work through it.
This creates a constant tension: thoroughness versus speed. Every classifier knows the pull between doing the careful, methodical work that classification demands and the mounting backlog that demands faster turnaround. The pressure to “just get it done” is real… and dangerous.
Volume pressure would be manageable if classifications were low-consequence decisions. They’re not.
On the export side, a wrong classification can trigger a cascade of failures. An incorrect jurisdiction or classification determination can mean your license applications are built on a faulty foundation. It can mean shipments you thought were license-free actually required authorization. It can mean years of transactions are suddenly suspect. These aren’t hypothetical risks; wrong classifications have been the basis of enforcement actions and consent agreements that resulted in millions of dollars in penalties and years of enhanced oversight.
On the import side, an incorrect HTS classification can mean improper duty payments, either overpaying (a direct hit to margins) or underpaying (creating liability that compounds over time). It can trigger CBP scrutiny, audits, and penalties. For companies operating on thin margins or high volumes, the financial exposure can be substantial.
The stakes create a paradox: the pressure to move fast collides with the reality that mistakes can be very costly. And unlike many business decisions where errors can be quickly corrected, classification mistakes often aren’t discovered until months or years later, when the exposure has already accumulated.
Classification doesn’t exist in isolation. It sits squarely in the path of business operations, and business has its own imperatives: ship faster, ship more, reduce costs.
Sales teams need products and documentation cleared for export now to close deals. Supply chain teams needed import classifications yesterday to keep production lines running. Finance wants to know why compliance is adding lead time and cost. Product teams wonder why a “simple” classification is taking so long.
These pressures aren’t illegitimate; they’re just the realities of running a business. But they create an environment where compliance professionals face constant pressure to cut corners, make assumptions, or defer difficult questions. The path of least resistance is rarely the path of best compliance.
I’ve seen well-intentioned teams develop informal shortcuts: defaulting to “safe” classifications without proper analysis, copying classifications from similar-seeming items without verification, or treating preliminary classifications as final. These adaptations are understandable responses to pressure, but they create risk that may not surface until an audit or investigation.
The legal frameworks underpinning trade classification don’t offer much room for error.
Export controls operate under a strict liability standard. Intent doesn’t matter: if an unauthorized export occurred, liability attaches. BIS and DDTC have demonstrated repeatedly that they will pursue enforcement actions for classification failures, even when companies believed in good faith they were compliant.
Import classifications operate under the “Reasonable Care” standard established by the Customs Modernization Act (Mod Act). CBP expects importers to exercise reasonable care in classifying goods, and the bar for what constitutes “reasonable” continues to rise.
Both regimes carry civil penalties that can reach into the millions. But here’s what keeps compliance professionals up at night: willful violations can result in criminal liability, for companies and for individuals. Prison time is a real specter for those who knowingly disregard classification requirements or engage in deliberate evasion.
This personal liability dimension adds weight to every classification decision. It’s not just the company’s money at risk: it’s the classifier’s professional reputation and, in extreme cases, personal freedom that’s on the line.
So how do classification teams succeed in this pressure cooker environment? The best teams I’ve seen share common characteristics:
Start with leadership commitment. A clear, uncompromising commitment to compliance from management creates air cover for teams to do the work right. When leadership treats compliance as a cost center to be minimized, teams get the message and shortcuts follow. When leadership treats compliance as a strategic priority, teams have the support they need to push back on unreasonable timelines and resource classification properly.
Build clear policies that meet regulator expectations. Guidance from DDTC, BIS, OFAC, DOJ, and CBP should serve as roadmaps for meeting regulator expectations. Policies that align with these frameworks not only reduce risk, they provide teams with clear standards to apply under pressure.
Develop detailed implementing procedures. Policies set direction; procedures enable execution. The best teams have documented, step-by-step procedures for classification that ensure consistency, support training, and provide evidence of systematic compliance in case of audit or investigation.
Equip teams with the right tools. When classification demands are high and stakes are significant, teams need systems that bake in best practices, surface relevant information quickly, and help identify potential problems before they become costly mistakes. The right tools don’t replace expert judgment – they amplify, support, and turbocharge it, helping skilled professionals work more efficiently without sacrificing accuracy.
Book a Demo - See TCW in action with a personalized walkthrough of the modules most relevant to your products, jurisdictions, and trade flows.
Talk With an Expert - Connect with a trade compliance practitioner on our team to discuss your program, scope a pilot, or evaluate how TCW fits your operations.