The Sensor That Traveled Too Far: Bosch, Huawei and the Export-Control Rule Hidden in the Factory

I would like to discuss in detail the recent Robert Bosch (Bosch) export controls enforcement case, because it is HUGELY important in highlighting the importance of US Foreign Direct Product Rule-related controls, especially in multilayered production/supply chains. BIS enforcement announcement

Please, be patient, because the details matter! The products at issue were MEMS sensors – tiny microelectromechanical devices used in smartphones, wearables and cars – and automotive software. Useful, sophisticated, commercial. The sort of things that make a phone know which way is up, a wearable count a step, or a vehicle system do something more clever than merely blink a dashboard light. BIS itself described the MEMS sensors as having broad consumer applications, including in smartphones, wearable technology and automobiles.

Here’s a thing about export controls: they have a talent for making ordinary things complicated. Enter US FDPR! In this case, a German-made sensor sold from abroad to a Chinese technology company allegedly picked up US export-control jurisdiction because of the way it was made, and not because it was shipped from the US.

More precisely, the product was subject to the US jurisdiction because of the equipment, technology, software and third-party production steps behind the way it was made.

According to BIS, Bosch through non-US subsidiaries, exported from abroad approximately $72,369,361 worth of foreign-produced MEMS sensor products and automotive software to Huawei Technologies Co. and Huawei affiliates on the Entity List between September 16, 2020 and September 26, 2024, without the required BIS license or authorization.

The Justice Department described the same conduct as an alleged scheme to send products and software to an Entity-listed company in China where the items were manufactured with equipment that was the direct product of U.S. software or technology. DOJ identified the two Bosch subsidiaries involved as Bosch Sensortec GmbH and ETAS GmbH.

The Basic Case

BIS announced a $36,184,680 civil penalty against Bosch. BIS said Bosch filed a voluntary self-disclosure and cooperated with the investigation. BIS also said it was suspending approximately $3.6 million of the penalty as credit for disgorgement in the parallel DOJ matter. The case was investigated by BIS’s Office of Export Enforcement, New York Field Office. BIS enforcement announcement

DOJ, for its part, declined to prosecute Bosch. Still – not a free coffee after a long wait. DOJ conditioned the declination on Bosch’s agreement to disgorge $11,430,098 in pre-tax profits from the transactions. DOJ credited $7,829,069 paid by Bosch to BIS against that disgorgement amount, leaving an actual additional disgorgement payment of roughly $3.6 million.

What Bosch Was Making

Bosch makes products that feel like magic, until a BIS official or a lawyer describes them “items subject to the EAR”. Here’s what I have been able to piece together based on the enforcement documents and Bosch’s public statements.

Bosch Sensortec describes MEMS sensors as tiny microelectromechanical systems that detect mechanical, magnetic or chemical changes and convert them into electrical information. In a consumer device, they help enable functions like screen orientation, image stabilization, motion tracking, fitness activity detection, air-quality monitoring and other helpful features.

A MEMS sensor, in Bosch’s own description, contains a MEMS element packed in a semiconductor housing together with an ASIC, an application-specific integrated circuit. Some components inside the smallest MEMS sensors are only four microns in size. In human terms, that is tiny, but it is still large enough to carry a compliance program on its back.

Bosch says it designs and manufactures MEMS sensors in-house, with MEMS sensors manufactured in Reutlingen and Dresden, Germany. The process takes more than three months and involves several hundred steps under exacting cleanroom conditions. Bosch’s own historical account describes MEMS production as a four-stage process using ultra-thin silicon wafers; by etching and depositing material, high-precision structures are embedded into silicon, creating chips with structures thinner than a human hair. Bosch MEMS production history

Bosch’s Reutlingen wafer-fab materials describe the site as involving semiconductor frontend manufacturing and a backend semiconductor test center, with manufactured products including ASICs, power semiconductors and MEMS. Bosch also says its broader semiconductor production network includes wholly owned wafer fabs and test centers, and is extended by numerous silicon foundry partners and OSATs – outsourced semiconductor assembly and test providers.

This is all HUGELY complex and INCREDIBLY important for FDPR analysis.

  • What technology was used?
  • What software was used?
  • What equipment was essential?
  • Who tested the item?
  • Who packaged it?
  • Who made the ASIC?
  • What plant or major component was involved?

FDPR Made Germany Feel Closer to the US

Let’s restate the rule. Under the EAR, foreign-produced items outside the United States can become subject to US export controls if they are the direct product of specified US-origin technology or software, or if they are produced by a complete plant or major component of a plant that is itself the direct product of specified US-origin technology or software. The regulation says a “major component” includes equipment essential to production, including testing equipment. 15 C.F.R. § 734.9

For Entity List Footnote 1 parties, the rule has two essential pieces.

  • First, the product scope. The foreign-produced item can be covered if it is the direct product of specified technology or software subject to the EAR, or if it is produced by a plant or major component of a plant that is itself the direct product of specified US-origin technology or software.
  • Second, the end-user scope. The rule can be triggered if there is knowledge that a Footnote 1 Entity List party is involved as a purchaser, intermediate consignee, ultimate consignee or end user, or if the item will be incorporated into or used in the production or development of an item produced, purchased or ordered by such an entity.

Here’s how the FDPR issue appears to have attached to Bosch’s products:

Bosch export controls enforcement and Entity List FDPR flowchart

The Third-Party Problem: the Invisible Middle of the Supply Chain

I would argue that the most interesting sentence in the DOJ declination letter is the sentence about third parties.

DOJ said the investigation identified ongoing sales despite “several missed opportunities where third-party companies identified potential applications of the FDPR to their products or equipment used in the provision of their services.” DOJ declination letter

That is a dense government sentence. In plainer English: other companies appear to have told Bosch, or at least put Bosch on notice, that the way some products or services were being made or provided might trigger the FDPR. Bosch, according to DOJ, did not use those warnings to stop the sales.

This made the case materially more complex. In addition to screening Huawei and understanding their own in-house products, it was also a matter of understanding whether third-party manufacturing, testing, packaging, ASIC production, service provision or software testing caused a foreign-produced Bosch item to become subject to the EAR.

The official DOJ materials do not name the third parties or describe each production step. But secondary reporting that appears to summarize BIS charging materials gives a more detailed account. According to that reporting, the MEMS sensor portion involved 11 sensor models: nine using MEMS chips produced on Bosch’s German lines with epitaxy machines supplied by an anonymized Company One, and two using ASICs made by an anonymized Company Two on equipment reportedly within FDPR scope. The same report states that the software portion involved CycurHSM automotive firmware from ETAS and testing using a microcontroller supplied by an anonymized Company Three. It further describes warnings from an outsourced packaging/testing provider, a supplier certification involving epitaxy equipment, and a prospective foundry that allegedly warned Bosch it could not supply Huawei without a BIS license. secondary reporting

The Alleged Production Paths

Again, according to the public sources: foreign-produced Bosch products and software were made with equipment that was the direct product of U.S. software or technology, and third-party companies raised possible FDPR issue. The detailed production-path allegations below rely on secondary reporting and may not be 100% accurate. However, it is still worth considering.

On the reported MEMS side, nine sensor models allegedly depended on epitaxy machines used to deposit layers of silicon or other materials on wafer substrates, creating multilayer crystalline structures for MEMS chips. If the epitaxy equipment was a “major component” of the production plant and was itself the direct product of covered US-origin technology or software, the FDPR analysis would not care that the machines were sitting abroad or supplied by a non-US company. secondary reporting

For two other sensor models, the reported issue was the ASIC. Bosch’s own materials explain that a MEMS sensor module includes a MEMS sensor element packed together with an evaluation circuit, the ASIC. Bosch wafer fabrication materials

If an ASIC is an integral component of the finished sensor, and if that ASIC is produced by a third-party foundry using equipment or a plant that falls within the FDPR, the compliance question becomes all about the third-party foundry’s production environment.

This is where ordinary screening tools tend to sigh and ask for a vacation – figuratively speaking.

The software path is even more subtle and complex. Secondary reporting identifies the ETAS product as CycurHSM automotive firmware software and states that the firmware allegedly required testing using a microcontroller supplied by a third party, and that the testing step was part of the production process.

Remember that the EAR definition of production expressly covers testing and quality assurance.

This is easy to miss. Even if the deliverable is software, the compliance analysis should ask how the software was developed, validated, tested, compiled, delivered, updated or maintained.

To recap: here’s where third-party complexity could have entered the Bosch fact pattern:

Bosch MEMS and software production paths under FDPR

What Went Wrong

A couple of things.

DOJ said Bosch’s trade compliance personnel were “ill-equipped” to provide accurate FDPR guidance. This suggests that the company perhaps had people assigned to trade compliance, but not enough people with the right export-control technical expertise to resolve a difficult FDPR question involving foreign-produced sensors, software, Huawei, production equipment, third-party suppliers and non-US subsidiaries.

The controls appear to have failed at several points.

  • The company appears to have lacked a reliable production-chain jurisdiction file. Bosch needed to know what equipment, tools, software, technology, ASIC production steps, foundry services, packaging, testing and quality-assurance processes touched the items. They did have enough to cover that.
  • Third-party warnings did not become hard stops. DOJ says third parties identified potential FDPR applications to their products or equipment used in providing services. A warning of that sort should have triggered shipment holds, legal review, document preservation and senior compliance sign-off.
  • The company appears to have blurred de minimis and FDPR concepts. Some public sources describe internal confusion between US-content analysis and FDPR analysis. Those are different questions. De minimis analysis asks whether a foreign-made item contains more than a certain percentage of controlled US-origin content. FDPR analysis can apply even where the item does not contain controlled US content, if the production process used covered US technology, software, equipment, plant components or testing equipment.
  • Last but not least: software seems to have been at risk of falling outside the company’s mental model of export controls.

What Proper Controls Would Have Looked Like

On the facts as described above: a properly designed control system would have treated Huawei sales as a license-or-stop environment – no product could move, no software could be delivered, no maintenance release could be issued, and no sales team could “just check one more thing with the customer” until trade compliance completed a documented FDPR analysis.

  • The first control would have been a regulatory-change control. When the Huawei FDPR expansion took effect, Bosch should have triggered a group-wide Huawei transaction freeze for all non-US subsidiaries, including Bosch Sensortec and ETAS. The freeze should have covered shipments, samples, replacements, software downloads, firmware, maintenance, support, license keys, updates and indirect sales through distributors.
  • The second control would have been a production-chain map. For each Huawei-bound MEMS sensor, Bosch should have maintained a jurisdiction file showing the MEMS element, ASIC, wafer fabrication steps, epitaxy, deposition, etching, packaging, testing, quality assurance, supplier equipment, foundry tools, OSAT involvement, and any US-origin technology or software behind the plant or major component of the plant. This is likely the hardest part.
  • The third control would have been a software-specific FDPR review. For ETAS, that meant mapping how the software was developed, compiled, tested, validated, updated and maintained. If testing involved a microcontroller or test equipment that was itself produced from covered US technology or software, the software team needed to know that before delivery to Huawei.
  • The fourth control would have been third-party certification. Suppliers, foundries, equipment providers, packaging houses and test providers should have been required to certify whether their equipment, plant, software or services created FDPR exposure for Huawei Footnote 1 transactions. The EAR itself recognizes supplier certifications as a way to assist companies in resolving potential red flags, while making clear that certification is not the only due-diligence step required.

Bosch FDPR compliance controls and transaction review flowchart

Closing Remarks

Many companies build export-control programs around three familiar questions: What is the item? Where is it going? Who is the customer? These are important and relevant questions.

The FDPR adds a fourth question that can be more difficult than the first three: How was the item made?

For a global manufacturer, that question may involve equipment suppliers, chip foundries, software tools, test labs, microcontrollers, quality-assurance processes, internal design centers and subsidiaries that do not think of themselves as operating anywhere near US jurisdiction.

That is the trap. The business sees a German sensor. The FDPR sees a genealogy covered under the EAR.

The Bosch resolution shows that regulators expect companies to know that genealogy when selling to a Footnote 1 Entity List party like Huawei. They expect legal and compliance teams to understand not only the customer, but the equipment and technology behind the product. They expect third-party warnings to freeze the production cycle.

Here’s my version of the lesson learned from a small sensor: in modern export controls, the most important part of the shipment may be the part that never ships at all – the technology, software and production equipment quietly sitting behind the factory door.

Disclaimer: this summary is provided for informational and educational purposes only and does not constitute legal advice. It is intended to offer a general overview of recent regulatory developments based on publicly available information. Readers should not act upon this information without seeking specific legal or compliance advice tailored to their particular circumstances. No attorney-client relationship is created by this summary, and the author assumes no responsibility or liability for any actions taken or not taken based on its contents. 

Subscribe Newsletter

Get the latest insights straight to your inbox.

Back to top