Select your language
Blog
Blog description
Artificial Intelligence and OFAC Sanctions: Emerging Legal Risks for U.S. Companies
Artificial intelligence is rapidly becoming part of ordinary business infrastructure. Companies now use AI to provide professional services, operate cloud platforms, automate procurement, generate software, administer payments, manage logistics, analyze investments, support customers, design products, and make increasingly autonomous commercial decisions.
That creates a new question for U.S. sanctions compliance.
The issue is no longer limited to whether an AI company may sell a particular technology abroad. Companies across industries must consider whether the use, provision, financing, hosting, customization, or distribution of AI can create a transaction prohibited by the U.S. Department of the Treasury’s Office of Foreign Assets Control (“OFAC”).
OFAC does not administer a separate sanctions regime for artificial intelligence. Existing sanctions rules apply to AI-related transactions in the same way they apply to other goods, services, technology, property, and financial activity.
What is changing is the factual environment in which those rules operate.
AI can allow a service to be delivered instantly across borders. A cloud platform can provide computing functionality to users in multiple jurisdictions without a traditional physical export. An AI agent can initiate purchases or payments with limited human involvement. A third-country distributor can provide access to technology whose ultimate user is located in a sanctioned jurisdiction. Synthetic identities and AI-generated corporate materials can also make the ultimate parties to a transaction more difficult to identify.
For U.S. companies, the legal question should therefore be broader than whether “AI is permitted.”
The relevant questions are:
- What is being provided
- To whom
- Where is the ultimate benefit received
- Who owns the counterparty
- How is the transaction being paid for
- Which OFAC sanctions program applies?
AI Is Not Outside the Existing OFAC Framework
U.S. sanctions are generally technology-neutral.
If U.S. law prohibits a person from providing a particular service to a sanctioned person or jurisdiction, using AI to perform that service does not ordinarily change the underlying legal character of the transaction.
A U.S. consulting firm, for example, does not necessarily avoid a prohibition on providing management consulting services merely because much of its analysis is generated through an AI platform.
Likewise, a company cannot assume that providing a prohibited service through an automated platform rather than through employees places the activity outside OFAC jurisdiction.
The same principle applies when AI itself is the service being provided. Depending on the circumstances, an AI transaction may involve:
- Software;
- Cloud computing;
- Software-as-a-Service;
- API access;
- Technical assistance;
- IT consultancy;
- Data processing;
- Professional services;
- Model customization;
- Training;
- Engineering;
- Financial services;
- Digital assets;
- Technical support;
- Computing infrastructure.
The applicable sanctions analysis will depend on the substance of the activity rather than the marketing label attached to it.
Russia Provides an Important Example
The Russia sanctions program illustrates how existing service restrictions can apply to AI-related business.

The restrictions include IT consultancy and design services, as well as certain IT support and cloud-based services involving enterprise-management software and design-and-manufacturing software.
OFAC explains that IT consultancy and design services include the development and implementation of software and assistance or advice concerning software development and implementation.
This can become relevant to AI in several ways.
Consider a U.S. company that:
- Develops a customized AI application for a Russian enterprise;
- Modifies an AI-enabled application for use within a Russian company's internal IT environment;
- Provides implementation advice concerning an AI-based business system;
- Integrates AI functionality into enterprise software;
- Provides technical assistance concerning implementation of customized AI software.
Depending on the facts, some of these activities could fall within OFAC's definition of IT consultancy and design services.
At the same time, companies should avoid assuming that every AI service to Russia is categorically prohibited by this particular determination. The scope of the restriction depends on the nature of the service, the underlying software, available exclusions, licenses, and potentially applicable Commerce Department authorizations. OFAC expressly recognizes exclusions involving certain software authorized or licensed under the Export Administration Regulations.
The correct analysis therefore requires examining the actual functionality and service being supplied.
The Ultimate Recipient May Matter More Than the Contracting Party
AI business models frequently involve multiple layers.
A U.S. company may license a platform to a distributor in the UAE, Switzerland, Turkey, Kazakhstan, Singapore, or another third country. That distributor may then provide access to affiliates or customers elsewhere.
The fact that the immediate customer is outside a sanctioned jurisdiction does not necessarily resolve the sanctions question.
In its Russia guidance, OFAC expressly states that the indirect provision of certain prohibited services includes situations where the benefit of those services is ultimately received by a person located in Russia.
OFAC provides examples involving third-country companies and resellers supplying software or support to Russian recipients.
That principle is especially important for AI because digital services can be redistributed easily.
Potential risk structures include:

The contracting entity may therefore be only part of the analysis.
Companies should understand not only who pays for a service but also who will use it and where its benefit will ultimately be received.
AI Makes “Provision of Services” More Difficult to Define Operationally
Traditional international commerce often involved identifiable delivery events: a container crossed a border, software was downloaded, or a consultant traveled abroad.
AI changes that model.
A company may continuously provide functionality through remote infrastructure without making any conventional shipment.
Consider:

Each transaction may occur in seconds and may involve a customer located in one country, users in another, computing infrastructure in a third jurisdiction, and payment through a fourth.
That architecture does not eliminate sanctions obligations. It makes identifying the legally relevant parties and services more complicated.
Professional Services Firms Also Face AI-Related OFAC Risk
The issue extends well beyond software developers. U.S. companies increasingly incorporate AI into traditional professional services.
Examples include:
- Management consultants using AI to develop strategic recommendations;
- Accountants using AI to prepare financial analyses;
- Engineers using AI-assisted design systems;
- Architects generating technical designs through AI;
- Investment advisers using AI to analyze portfolios;
- Law firms using AI to assist with research or document analysis;
- Marketing firms using generative AI to create campaigns;
- Corporate-formation providers using automated platforms;
- Financial institutions using AI to structure transactions.
Where the underlying service is prohibited by an applicable sanctions rule, the use of AI does not necessarily alter the prohibition.
This is particularly relevant under the Russia sanctions program, where OFAC has imposed restrictions on categories including:

OFAC has also stated that the indirect provision of such services may be prohibited when the ultimate benefit is received by a person located in Russia.
Businesses therefore need to analyze the substantive service being delivered, not merely the technology used to produce it.
AI Cloud Access Presents a Distinct Issue
Cloud computing is becoming increasingly inseparable from AI.
Many companies do not receive AI software at all. Instead, they receive access to computing capacity, hosted models, APIs, or cloud-based applications.
Whether a particular cloud service is prohibited depends on the applicable sanctions program and the characteristics of the service.
For Russia, OFAC's IT and Software Services Determination expressly covers certain cloud-based services involving specified categories of enterprise-management and design-and-manufacturing software. OFAC also recognizes circumstances in which services related to software authorized by the Department of Commerce may fall within an exclusion.
Iran illustrates why the analysis must remain program-specific.
Under the Iranian Transactions and Sanctions Regulations, OFAC authorizes certain fee-based and no-cost cloud services and software that are incident to communications over the internet, subject to detailed conditions. The authorization includes certain cloud-based services and qualifying communications software.
The existence of these authorizations does not create a general authorization for all AI or cloud services to Iran.
Rather, it demonstrates a fundamental principle of sanctions law:

Neither approach may accurately reflect the applicable regulations.
Blocked Persons Can Create Risk Even Outside Sanctioned Countries
Geography is only one element of OFAC compliance.
A prohibited AI transaction can occur in London, Dubai, New York, Singapore, or another location if the relevant transaction involves a blocked person or blocked property.
OFAC generally prohibits U.S. persons from dealing with persons whose property and interests in property are blocked. The restrictions may also apply to entities that are not expressly listed.

For AI-related business, this can affect:

A startup incorporated in an otherwise low-risk jurisdiction could still be blocked because of its ownership.
Similarly, several blocked investors holding separate interests may collectively cause an entity to reach OFAC's 50 percent threshold because OFAC aggregates ownership by blocked persons.
Artificial Intelligence Can Make Sanctions Evasion More Sophisticated
AI is also changing the conduct that compliance systems must detect.
Treasury's 2026 National Money Laundering Risk Assessment identifies artificial intelligence among the emerging technologies that illicit actors can use to increase the size, scope, and speed of unlawful schemes.
AI can potentially facilitate:
- Synthetic identities;
- Artificial corporate profiles;
- False business websites;
- Fabricated invoices;
- Deepfake video or audio;
- Automated creation of corporate documents;
- Large-scale phishing and impersonation;
- Concealment of the real purpose of transactions.
For international companies, this means that documents appearing professional and internally consistent may no longer provide the same level of comfort they once did.
A sophisticated website, corporate profile, business plan, invoice package, or video conference may be generated or manipulated using AI.
The legal consequence is not that every transaction requires forensic investigation. It is that companies should reassess the weight they place on documentation when other risk indicators are present.
AI Infrastructure Can Become Part of a Sanctions-Evasion Supply Chain
Artificial intelligence also depends on physical infrastructure.
Advanced servers, processors, data-center equipment, networking components, cooling systems, and other technology can become part of sanctions and export-control enforcement.
The Treasury has already targeted third-country procurement networks supplying advanced technology to Russia. In one sanctions action, Treasury described shipments of U.S.-trademarked advanced servers designed for artificial intelligence and machine learning to Russian technology companies, illustrating how AI infrastructure can become part of a broader sanctions-evasion or military-procurement concern.
For manufacturers, distributors, logistics providers, financial institutions, and investors, the lesson is important.
AI risk is not confined to companies selling algorithms.
It can arise from supplying:
- GPUs;
- Servers;
- Data-center infrastructure;
- Networking equipment;
- High-performance computing systems;
- Components;
- Financing;
- Logistics;
- Technical services.
Many of these transactions also implicate the Export Administration Regulations administered by BIS.
OFAC and BIS jurisdiction should therefore be considered together where advanced computing technology is involved.
AI Agents Could Create a New Transaction-Control Problem
One of the most significant emerging issues involves increasingly autonomous AI agents.
Companies are beginning to use AI systems capable of:
- Selecting suppliers;
- Negotiating purchases;
- Generating purchase orders;
- Booking transportation;
- Selecting payment methods;
- Initiating payments;
- Purchasing digital services;
- Managing cloud resources.
This creates a fundamental sanctions question:
What happens when the transaction decision is made by software rather than by an employee?

OFAC may impose civil penalties on a strict-liability basis under applicable sanctions authorities, meaning a person subject to U.S. jurisdiction can potentially face civil liability even without knowledge that it was participating in a prohibited transaction.
Accordingly, “the AI made the purchase” is unlikely to function as a general legal defense to an otherwise prohibited transaction.
Companies deploying autonomous agents should therefore consider what transactions the agent is authorized to initiate, which counterparties it can select, whether it can change payment destinations, whether human approval is required above specified thresholds, and how transaction decisions can later be reconstructed.
AI and Automated Payments
AI-powered commerce increasingly intersects with digital payments.
An AI system may eventually be able not only to recommend a transaction but also to execute one through a bank account, payment processor, stablecoin, digital wallet, or other financial infrastructure.
OFAC has made clear that sanctions obligations do not disappear because a transaction uses digital currency rather than traditional fiat currency. U.S. persons remain responsible for avoiding unauthorized dealings involving blocked persons and prohibited transactions.
Companies developing AI systems with payment authority therefore face two layers of risk:
First, the underlying commercial transaction must be permissible.
Second, the payment itself must not involve blocked property, prohibited financial institutions, or other restricted parties.
The more autonomous the system becomes, the more important it is to establish legal controls before transactions are executed rather than attempting to review them after completion.
U.S. Employees and Contractors Can Create Jurisdictional Exposure
Multinational companies should also consider who is performing AI-related work.
Many OFAC restrictions apply to U.S. persons wherever located.
A U.S. citizen working for a foreign company may therefore have obligations that differ from those of non-U.S. colleagues.
OFAC's Russia guidance illustrates the point. OFAC has stated that a U.S. person may not provide certain prohibited IT and software services to an employee or contractor located in Russia merely because that worker is employed directly by a U.S. company or a third-country company.
Multinational businesses should therefore examine:

AI systems often operate globally, but OFAC jurisdiction remains tied to legally relevant persons and transactions.
AI Can Blur the Boundary Between Product and Service
Sanctions regulations frequently distinguish between goods, software, information, and services.
AI can make those distinctions less obvious.
A customer may receive:
- Access to a model;
- Customized model training;
- Consulting concerning model deployment;
- Cloud computing;
- Software;
- Technical support;
- Data;
- Generated reports;
- Automated decision-making.
A single commercial contract may contain several of these elements simultaneously.
That means companies should resist classifying the entire transaction simply as a “software subscription” or “AI license.”
The legal analysis should identify each component of the commercial relationship and determine whether a particular sanctions prohibition, exemption, general license, or specific license applies.
Third-Country Resellers Require Particular Attention
Many U.S. companies expand internationally through distributors and resellers.
AI services can make traditional distribution controls particularly difficult because access can be reassigned electronically and the provider may have limited visibility into the ultimate user.
Contractual protections therefore become increasingly important.
Depending on the risk profile, agreements with distributors may need provisions addressing:
- Prohibited jurisdictions;
- Blocked persons;
- Ultimate end users;
- Resale or sublicensing;
- Remote access;
- Use by affiliated companies;
- Geographic restrictions;
- Changes in ownership;
- Audit rights;
- Termination following sanctions events.
A contractual representation cannot itself authorize a prohibited transaction.
But clear contractual restrictions can help establish the commercial controls necessary to prevent a distributor from turning an otherwise permissible relationship into an indirect prohibited service.
Sanctions Clauses Need to Evolve for AI Transactions
Traditional sanctions clauses often state simply that neither party is sanctioned and neither will violate applicable sanctions laws. AI transactions may require more specificity.
Companies may need to address:
- Where users will access the system;
- Whether affiliates may use the system;
- Whether access credentials may be transferred;
- Whether APIs can be incorporated into third-party products;
- Whether the service may be resold;
- Where cloud infrastructure will be used;
- Who receives customized outputs;
- Whether prohibited jurisdictions may receive the benefit indirectly;
- Whether autonomous systems may initiate transactions.
The contract should reflect the actual technology architecture. A sanctions clause drafted for the sale of physical goods may not adequately address a platform that can be accessed instantaneously by thousands of users in multiple countries.
When a Potential AI-Related Sanctions Violation Is Discovered
When a company discovers that an AI service, payment, or technology may have reached a prohibited person or jurisdiction, the issue should be investigated promptly. Relevant questions may include:
- Who contracted for the service?
- Who paid?
- Who actually used the system?
- From which jurisdictions was it accessed?
- Did a distributor or affiliate provide access?
- When did the activity begin?
- What functionality was provided?
- What sanctions program applied at the time?
- Was the counterparty blocked?
- Was the counterparty owned by blocked persons?
- Was a general license or exemption potentially available?
- Did BIS authorization also apply?
- Are related transactions continuing?
AI and cloud platforms often generate substantial electronic records, including user-access logs, IP information, API histories, payment information, administrator changes, and account activity.
Preserving those records early may be essential in reconstructing what occurred.
Depending on the facts, the company may then need to evaluate blocking or rejection obligations, regulatory reporting, a specific-license application, remedial measures, or a potential voluntary self-disclosure.
OFAC Itself Is Entering the AI Era
The regulatory environment is also evolving.
In June 2026, OFAC and the United Kingdom's Office of Financial Sanctions Implementation reported that their bilateral cooperation included sharing experience concerning the use of artificial intelligence to support sanctions functions. The agencies expect emerging technologies to assist with information analysis and decision-making.
Treasury's broader 2026 work likewise recognizes AI as both a tool for combating illicit finance and a technology capable of increasing the scale and sophistication of illicit activity.
This suggests that AI will increasingly appear on both sides of sanctions enforcement: as technology used by businesses and illicit actors, and as technology used by regulators investigating those activities.
The Central Question Is the Transaction, Not the Technology
Artificial intelligence does not require companies to abandon traditional OFAC principles.
It requires them to apply those principles to new commercial structures.
Companies should ask:
- Who is receiving the AI-related service or technology?
- Who ultimately benefits from it?
- Where are those persons located?
- Who owns them?
- What exactly is being supplied?
- How is it delivered?
- Who pays for it?
- Can access be transferred or resold?
- Could an autonomous system execute a prohibited transaction without meaningful human review?
These questions apply not only to AI developers.
They apply to banks, investment firms, manufacturers, exporters, professional-services firms, cloud providers, logistics companies, fintechs, multinational corporations, and virtually any business integrating AI into cross-border operations.
Conclusion
Artificial intelligence is creating new business models, but it is not creating an exemption from U.S. sanctions law.
The principal legal risk is not that OFAC has created a separate category of “AI sanctions.” Rather, AI is changing how traditional sanctions issues arise.
A prohibited service may now be delivered automatically through a cloud platform. A third-country customer may provide AI access to a sanctioned end user. A blocked person may acquire an interest in an AI company that does not itself appear on an OFAC list. An AI agent may initiate transactions without contemporaneous human approval. AI-generated identities and documentation may make sanctions-evasion schemes more difficult to recognize. Advanced AI infrastructure may become part of a prohibited procurement network.
For U.S. companies, sanctions compliance therefore needs to follow the economic reality of the transaction.
The critical issue is not simply whether a company develops artificial intelligence or uses it.
The critical issue is whether AI changes who receives a product or service, who benefits from it, how a transaction is executed, and whether the resulting activity is authorized under the applicable OFAC sanctions program.
As AI becomes increasingly autonomous and deeply integrated into international commerce, that distinction will become more important, not less.

ES
RU
TR
FA
AR
ZH