China's Regulations on Exit and Entry Administration took effect on September 15, 2026. They give commerce officials a new tool: the power to stop a person at the border over an export-control or technology-trade violation. Beijing's case for the rule is not frivolous, but the design is a poor way to protect technology, and it will cost China more than it protects.
The strongest case for the rule
Every state controls sensitive technology, and enforcement against individuals is a normal part of that. Export controls only work if the people who hold controlled know-how can be held accountable. Officials briefing on the regulation framed the export-control clause as protection for industrial and technological security during a period of high-level opening-up, and China's National Immigration Administration published that explanation alongside the text. Washington, Brussels and Tokyo all restrict what their engineers may share with foreign parties, and the US can prosecute individuals for export violations. A state that fears talent leakage to rivals has an understandable interest in dealing with a suspect before they leave.
What the text actually does
State Council Order No. 841 was signed on July 22, 2026 and is published on the official gov.cn portal. Article 4, third paragraph, provides that when Chinese citizens violate export-control or technology import-export rules and "may endanger national industrial or technological security," the State Council's commerce and other competent departments may decide to bar them from leaving.
Three features separate this from ordinary export enforcement.
- A preventive threshold. The trigger is conduct that may endanger security, not a proven harm or a conviction.
- An administrative decision-maker. The Ministry of Commerce and other departments can decide, not a court.
- No stated duration. According to the Brownstein client alert, the two other grounds for citizen exit bans carry six-month to three-year ranges, while the export-control ground has no specified limit and is discretionary.
The undefined core term matters most. "Industrial or technological security" is not defined in the provision, and export-control law already covers a wide range of dual-use items and technical data. A researcher who shares a paper, an engineer who takes a job offer, or a manager who ships a controlled component can all fall inside a phrase this open.
Why it lands on AI talent
The Globe and Mail reported on August 11 that Beijing has already reportedly prevented senior AI engineers from travelling abroad amid fears that Western companies are poaching top talent. The new rule does not create that practice. It gives it a statutory home.
That is a real change, and not a purely cosmetic one. Informal restrictions are deniable and hard to challenge because there is nothing to point to. A formal rule is visible, which arguably improves predictability. But a visible rule with a vague trigger and no time limit makes every technical employee a potential subject of it, and every employer aware of that. Companies will hire fewer people who might later be trapped, and engineers will weigh that risk before taking sensitive roles.
The same Globe report cites a Safeguard Defenders analysis documenting a roughly tenfold rise in travel restrictions over five years, with about 136,000 court verdicts imposing exit bans in the prior year alone. Those figures come from the human-rights group, not from the government, and they cover court-ordered bans rather than the new administrative power. They do show that exit restrictions were already a growing instrument before this regulation added a new category.
Costs beyond China's borders
The regulation also reaches foreigners and companies. The Brownstein alert notes that entry denials of one to five years apply to foreigners who submit false visa materials, and that designation on countermeasure, unreliable-entity or malicious-entity lists triggers automatic entry denial. It also says companies that issue invitation letters bear responsibility for the accuracy of supporting documents. Multinationals with staff in technology, research, data, supply chain or cross-border deal roles now face personnel risk on top of regulatory risk, and Brownstein advises them to update travel and transaction protocols.
That is the wider pattern worth resisting. When a trade-control regime is enforced through a person's physical liberty, compliance stops being a business question and becomes a hostage question. Firms cannot price that risk, so they reduce exposure instead. For a country that wants foreign investment in advanced manufacturing and AI, that is a self-inflicted cost.
A more proportionate design
The legitimate goal, keeping controlled technology from leaving improperly, can be met with narrower tools that do not hold a person in place indefinitely.
- Define the trigger. Replace "may endanger industrial or technological security" with a reference to specific controlled-item lists, so an engineer can know whether they are in scope.
- Cap the duration. Use the six-month to three-year range that the other Article 4 grounds already apply.
- Require independent review. A court or an independent panel should confirm the ban within a fixed period, and the affected person should be told the grounds.
- Target the transfer, not the traveller. Seizing controlled materials, auditing data access and penalising unlicensed transfers address the actual leak without restricting movement.
Free movement of people is a core part of how technology and knowledge circulate. Researchers who can leave and return build the networks that make a country's science stronger. Rules that instead make travel depend on an official's discretion may slow the outflow of a few individuals, but they raise the price of every technical career in the country, and they push mobile talent to decide early where it will work. Enforcement against real export violations is legitimate. Enforcement by open-ended detention at the border is neither proportionate nor likely to work.