September 3, 2026|3 min read

BAE's Controls Never Fired Where the Export Happened

BAE's $36M ITAR penalty shows what happens when controls live in a policy binder, not at the point of export. And BIS just made that gap expensive.

Written by Carlos Alvidrez, with AI assistance in research · How we use AI

BAE's Controls Never Fired Where the Export Happened

Photo by Nathan Cima on Unsplash

Somewhere inside BAE Systems, more than a hundred times, a controlled export left the building. A part shipped. A drawing got emailed. Data crossed a border it was never cleared to cross. Every one of those was a transaction. Not one of them got stopped.

The State Department's Directorate of Defense Trade Controls just priced those transactions at $36 million. The lesson is not that BAE lacked a program. It is that the program never lived where the exports happened.

BAE had policies. It had training. It had a document that said, in effect, do not do the thing that then happened more than a hundred times. None of it touched the moment of export.

An export control is only a control if it fires at the transaction: the instant the shipment is created, the file attached, the foreign national granted access. That is the only place a violation can be stopped, because that is the only place a violation happens.

A policy PDF fires zero times per shipment. The training you took in March does nothing to the file you email in September. The control was never near the work.

The violation you can't see still compounds

Here is why this runs for years instead of days. When your control is a document, the only things that catch a violation are a manual audit, a whistleblower, or a regulator. None of those move at transaction speed.

So the distance between what the policy says and what the shipping system does compounds quietly. Every quarter it grows. Nobody books it, because nobody can see it. It is liability accruing in the dark.

Thirty-six million dollars across more than a hundred violations is roughly $350,000 apiece. If you booked it one transaction at a time, in real time, someone flinches at the first one. Booked all at once, years later, it lands as a single number with a press release attached.

The gap was free. Now it isn't.

For a long stretch, that accruing liability was effectively free. Markets do not price what regulators do not enforce, and export enforcement was thin.

That era is closing. The Bureau of Industry and Security's FY2025 report reads less like a filing than a mission statement: enforcement actions up eighteenfold. What was invisible is getting invoices attached. BAE's $36 million is an early one, not the last.

You may not ship defense articles. It does not matter. The pattern holds anywhere a control lives as a written policy instead of an enforced check at the point of the transaction. Data leaves through an integration nobody gated. Access gets granted outside the flow meant to approve it. The policy is immaculate. The transaction never reads it.

So do one thing Monday. Take the control you are proudest of, trace it to the exact transaction it governs, and answer three questions:

  • Does it fire at that moment, or somewhere else, later?
  • How many times did it fire last month?
  • Who owns that number?

If nobody can tell you how many times a control fired, you do not have a control. You have BAE's binder, quietly accruing.

The violations that price you next were free this morning. Which of yours has never once fired where the work actually happens?

Sources

Related governance guides