Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement requires both parties to comply with applicable export control laws and sanctions programs, including EAR, ITAR, and OFAC. Customers bear sole responsibility for export compliance related to how they use AWS services, including content transfer, processing, and region selection. Customers also represent and warrant that they and their financial institutions are not on any prohibited party lists maintained by the UN, U.S. government, EU, or member states.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision places sole responsibility for export control compliance on the customer for their specific use of AWS services, including content and workload characteristics, and requires affirmative representation that the customer and its financial institutions are not subject to sanctions. Violation of export control representations could constitute a material breach triggering immediate termination under Section 5.2(b)(ii).
Under Section 11.6, customers affirmatively represent that they and their financial institutions are not subject to sanctions or listed on prohibited party lists, and assume sole responsibility for ensuring their use of AWS services complies with applicable export control and sanctions regulations. Breach of these representations may constitute grounds for immediate suspension or termination under Sections 4.1 and 5.2(b)(ii).
Cross-platform context
See how other platforms handle Export Controls and Sanctions Compliance and similar clauses.
Compare across platforms →Monitoring
AWS has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In connection with this Agreement, each party will comply with all applicable import, re-import, sanctions, anti-boycott, export, and re-export control laws and regulations, including all such laws and regulations that apply to a U.S. company, such as the Export Administration Regulations, the International Traffic in Arms Regulations, and economic sanctions programs implemented by the Office of Foreign Assets Control. For clarity, you are solely responsible for compliance related to the manner in which you choose to use the Services or AWS Content, including your transfer and processing of Your Content, the provision of Your Content to End Users, and the AWS region in which any of the foregoing occur.Excerpt from AWS's Customer Agreement
1. REGULATORY LANDSCAPE: This provision directly implicates the Export Administration Regulations administered by the Bureau of Industry and Security, ITAR administered by the Directorate of Defense Trade Controls, and OFAC sanctions programs administered by the U.S. Department of the Treasury. For international customers, EU dual-use export control regulations and member state implementing legislation may also apply. The UN Security Council consolidated sanctions list is specifically referenced. Criminal and civil penalties under these frameworks are substantial and separate from contractual consequences. 2. GOVERNANCE EXPOSURE: High. The requirement that customers represent their financial institutions are not subject to sanctions is notable, as customers may not have direct control over or continuous visibility into the sanctions status of their banking relationships. Changes in ownership, financial institution relationships, or operational geographies may require re-evaluation of this representation. 3. JURISDICTION FLAGS: Customers operating in or serving users in sanctioned jurisdictions face elevated exposure. International customers subject to conflicting export control regimes (such as EU anti-boycott regulations that may conflict with U.S. sanctions requirements) should seek legal counsel on compliance obligations. Customers in the defense and aerospace sectors using AWS for workloads that may be subject to ITAR should confirm appropriate AWS GovCloud or ITAR-compliant service configurations. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should include export control screening as part of AWS account setup and ongoing compliance monitoring, including screening of any third parties accessing the account. The representation regarding financial institution sanctions status should be validated and documented at contract inception and reviewed periodically. Organizations using AWS for international data transfers should confirm that their AWS region selections do not inadvertently route traffic through sanctioned jurisdictions. 5. COMPLIANCE CONSIDERATIONS: Export control compliance programs should be reviewed to ensure they address cloud service use, including content classification for EAR and ITAR applicability, end user and destination screening, and AWS region selection for applicable workloads. Legal teams should assess whether any dual-use technology, encryption, or controlled data processed through AWS services requires export licenses or is subject to license exceptions.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The provision places sole responsibility for export control compliance on the customer for their specific use of AWS services, including content and workload characteristics, and requires affirmative representation that the customer and its financial institutions are not subject to sanctions. Violation of export control representations could constitute a material breach triggering immediate termination under Section 5.2(b)(ii).
Under Section 11.6, customers affirmatively represent that they and their financial institutions are not subject to sanctions or listed on prohibited party lists, and assume sole responsibility for ensuring their use of AWS services complies with applicable export control and sanctions regulations. Breach of these representations may constitute grounds for immediate suspension or termination under Sections 4.1 and 5.2(b)(ii).
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.