A German EAR99 Sensor Became U.S.-Controlled Because of the Machines That Made It
Primary lensExport controls
Sub-topicFDPR enforcement
Evidence base6 records used
Use caseExport-control exposure
The U.S. control traveled through the machines that made the sensor
On June 17, 2026, BIS announced a $36,184,680 civil penalty against Robert Bosch GmbH for 109 violations of the Export Administration Regulations. The conduct involved roughly $72.37 million in foreign-made MEMS sensors and automotive software supplied to Huawei-linked parties from September 2020 to September 2024. The products were EAR99 and largely foreign-made, with little or no incorporated U.S. content. They were still subject to the EAR.
The legal hook was the Huawei Footnote 1 Foreign Direct Product Rule, which reached the products because Bosch produced or tested them on equipment that was itself the direct product of U.S.-origin technology or software. The U.S. nexus lived in the tools, where a de minimis content analysis would never have looked. That is the jurisdictional core of the case, and it is why EAR99 commercial electronics can carry a U.S. export-control obligation that a bill-of-materials review misses.
A clean de minimis result was the wrong test
Bosch's German trade-compliance team ran a de minimis analysis, found controlled U.S.-origin content below the 25% threshold, and concluded the products were outside the EAR. The analysis was performed, but it answered the wrong legal question. That error then propagated across four years and 109 shipments.
The two rules answer different questions. The de minimis rule at 15 C.F.R. § 734.4 asks how much controlled U.S.-origin content is incorporated in the foreign-made item by value, generally measured against a 25% threshold. The technology and equipment used to design or produce the item are invisible to that test. The Foreign Direct Product Rule at 15 C.F.R. § 734.9 turns on a different question, whether the item itself was the direct product of specified U.S. technology or software, or whether it was made by a plant or a major component of a plant that is itself a direct product of such technology or software. A foreign item with zero incorporated U.S. content can be subject to the EAR if the tools that made it carry the U.S. nexus.
The applicable starting point is the August 17, 2020 Huawei FDPR expansion, published at 85 Fed. Reg. 51596. That rule removed the earlier produced-or-developed-by-Huawei limitation and shifted the inquiry to two questions: whether a Huawei Footnote 1 entity was a party to the transaction, and whether the foreign-produced item was made through covered U.S.-origin technology or software, or through a plant or major component of a plant that was itself the direct product of covered U.S.-origin technology or software. The Huawei Footnote 1 FDP rule now sits at § 734.9(e)(1).
How the Foreign Direct Product Rule reached each product
BIS traced the U.S.-origin production hook through three distinct paths. For the MEMS sensors, nine of eleven models were manufactured in Germany on epitaxy machines that were themselves the direct product of U.S.-origin technology or software and were a major component of Bosch's plant. Those machines deposit the silicon layers that form the sensor's core sensing structure. For the remaining two sensor models, the products contained an application-specific integrated circuit produced on equipment that was itself a direct product of U.S. technology and a major component of a plant.
The CycurHSM automotive software was captured through testing rather than fabrication. ETAS tested every release, including bug fixes and maintenance updates, on microcontrollers that were direct products of U.S. technology and a major component of the producing plant. Software was inside the FDPR analysis, because BIS treated the testing on covered microcontrollers as part of the production chain that brought the releases within scope.
Because Bosch had knowledge that Huawei-linked Footnote 1 entities were parties to the transactions, each foreign-made, foreign-shipped, EAR99 item required a BIS license. None was obtained. That reach is the enforcement signal. The Huawei FDPR can capture EAR99 commercial sensors and automotive firmware when the production or testing chain carries the U.S. technology hook.
What Bosch got wrong
The violations flowed from a thin compliance function and an error that was never corrected. Bosch's U.S. export-controls team consisted of two people, one of whom split time with customs. An August 25, 2020 internal email advised Bosch Sensortec management that products below the 25% U.S.-content threshold would have no licensing requirements. The Order describes that advice as erroneously commingling de minimis with the FDPR, which turns on production equipment rather than incorporated content.
Bosch then failed to escalate at least five external red flags. A semiconductor assembly and test provider warned in September 2020 that transfers of its worked products to Huawei might be prohibited. A supplier sent an end-user certification in February 2021 expressly referencing the FDPR and Footnote 1. In June 2023 another supplier cited the FDPR and the Seagate $300 million penalty directly to Bosch, and Bosch's compliance professional dismissed it as the supplier's internal policy rather than a U.S. requirement. Bosch personnel signed supplier certifications promising not to ship to Footnote 1 entities while continuing to ship to Huawei, later saying they did not understand that Huawei carried a Footnote 1 designation. For ETAS, the error was simpler: Bosch personnel treated software as outside the FDPR. It was not.
How the penalty is structured so Bosch pays once
The BIS and DOJ resolution is built so Bosch pays the penalty amount one time. On the BIS side, the total civil penalty is $36,184,680. Bosch pays Commerce $32,583,651 within 30 days, and the remaining $3,601,029 is suspended pending the DOJ disgorgement payment and then credited toward the total.
On the DOJ side, Bosch disgorges $11,430,098 in pre-tax profits, but DOJ credits $7,829,069 of Bosch's BIS payment against that amount, leaving an actual disgorgement payment of about $3.6 million. The net effect is that Bosch's out-of-pocket payment to the U.S. government totals $36,184,680, allocated between the BIS civil penalty and the DOJ disgorgement that is credited back against the BIS penalty. Bosch does not pay DOJ a separate $11.43 million on top.
Why the declination matters
DOJ's National Security Division declined prosecution under the Export Control Reform Act, citing four factors, a voluntary self-disclosure filed while Bosch's internal investigation was still ongoing, cooperation, remediation that included adding 66 employees to its trade-compliance organization, and the adequacy of the parallel BIS penalty. DOJ accepted that Bosch's mistakes did not rise to willfulness, which is the standard for criminal liability.
This is the first NSD declination under the department-wide Corporate Enforcement Policy announced March 10, 2026. It is not the first NSD export-controls declination ever. MilliporeSigma in May 2024 preceded it under the prior NSD-specific policy, but that company was a fraud victim that gained nothing and paid no disgorgement. Even multi-year, profit-generating FDPR violations can avoid criminal prosecution where there is early self-disclosure, cooperation, remediation, and no willfulness or aggravating factors. The declination protects the company rather than individual employees, and DOJ reserved the right to reopen.
Where Bosch sits against Seagate
At $36.18 million, Bosch appears to be the largest publicly announced Huawei-FDPR resolution after Seagate, which drew a $300 million BIS penalty in April 2023 for EAR99 hard drives caught by the same production-tool logic. Seagate is the closest comparator, and it is the very case a Bosch supplier cited as a warning that went unheeded. Bosch drew a smaller penalty than Seagate, but the product reach is wider. The FDPR theory moved from hard drives into MEMS sensors and automotive firmware, confirming that EAR99 commercial electronics can be captured when the production or testing chain carries the U.S. technology hook.
What compliance teams should check now
Map production tools, rather than only the bill of materials. A clean de minimis result is worthless if a manufacturer has not asked whether its manufacturing and testing equipment is itself a direct product of U.S. technology or software in the listed 3D, 3E, 4D, 4E, 5D, and 5E ECCNs. Equipment provenance has to be inventoried across every production stage, including contract assembly and test, and the de minimis and FDPR analyses have to run as independent gates because the conflation between them was the single most expensive error in this case.
Supplier FDPR and Footnote 1 certifications and end-user questionnaires should function as escalation triggers routed to qualified U.S. export-controls counsel, rather than routine paperwork. Five separate warnings reached Bosch and none was escalated correctly. The compliance function also has to be staffed to the scale of the regulatory exposure. A two-person U.S. team advising a global enterprise was found to have contributed directly to the violations, and Bosch's remediation benchmark of 66 new hires signals what regulators consider adequate at that scale. A company that finds a violation should self-disclose early, before the internal investigation is complete, because early disclosure was the decisive factor separating a declination from prosecution here.
Bottom line
This was a production-tool case under the Foreign Direct Product Rule rather than a de minimis content case. A foreign-made, EAR99 sensor or firmware release becomes subject to the EAR when the equipment that made or tested it is itself a direct product of U.S. technology or software and a Footnote 1 entity is a party. Companies selling into restricted-party supply chains should treat equipment provenance, supplier certifications, and FDPR-versus-de-minimis gating as the controlling questions, because a content-only screen can clear products that BIS still treats as licensable.
Caveats
Unintentional is a legal term here rather than a factual one. Bosch characterized the violations as unintentional and DOJ accepted the absence of willfulness, but the conduct spanned 109 shipments over four years through repeated ignored warnings. The word describes the legal absence of willful intent, and BIS expressly found that Bosch's compliance failures contributed directly to the violations.
Supplier names and the specific controlling ECCNs of the U.S.-origin production equipment are redacted in the public documents. The Footnote 1 product-scope ECCN list has also been expanded since the August 2020 Huawei FDPR rule, so the rule text in effect at the relevant time should be distinguished from the broader current eCFR formulation.
On dates, the DOJ declination letter was signed June 15, 2026, the BIS Settlement Agreement and Final Order are dated June 16, 2026, and the public announcement came June 17, 2026. Some secondary outlets date the announcement June 18.
Source base
Figures and quotations are drawn from primary sources, the BIS press release and the underlying BIS Final Order, Settlement Agreement, and Proposed Charging Letter, the DOJ National Security Division declination press release and the executed declination letter, and the eCFR and Federal Register regulatory text at 15 C.F.R. § 734.4, 15 C.F.R. § 734.9, and 85 Fed. Reg. 51596. Where working figures diverged from the primary documents on the disgorgement and crediting structure, the primary documents govern. The penalty total of $36,184,680, the disgorgement figure of $11,430,098, and the conduct dates of September 2020 to September 2024 are confirmed in the BIS and DOJ announcements.
Free account
Keep reading with a free account.
Today's analysis is open to everyone. A free account opens the full archive and full tool output. No card required.