All briefings
P·3 — Defence & Dual-Use[ 46.05°N · 14.51°E · DUAL-USE ]
DUAL-USE STARTUP

Dual-use is not a dual-problem : What is exactly a Dual-Use Startup?

A practical guide to dual-use startups, EU export controls, licensing, FDI screening and what founders should check before scaling.

Dual-use is not a dual-problem :  What is exactly a Dual-Use Startup?

A startup can begin with a completely civilian product and still find itself dealing with defence regulation.

An autonomous drone may inspect infrastructure and also support reconnaissance. Advanced sensors may monitor industrial equipment and also have military applications. Encryption, AI, quantum technologies, robotics, semiconductors and advanced materials can all move between civilian and security environments.

That is where the term dual-use startup comes in.

But there is an important legal distinction. EU law does not create a separate legal status called a “dual-use startup”. Instead, it regulates particular goods, software and technologies that may have both civilian and military uses. For founders, the practical question is therefore not simply whether the company considers itself a defence business. It is whether its technology, transactions, customers or destinations bring it within export-control and related regulatory regimes.

What is a dual-use startup?

A dual-use startup develops technology with meaningful applications in both civilian and defence, security or other strategically sensitive markets.

The EU Dual-Use Regulation defines dual-use items as items, including software and technology, that can be used for both civil and military purposes. The definition also covers certain items connected to the development, production or use of nuclear, chemical or biological weapons and their means of delivery. (Eur-Lex)

That definition is broader than physical products.

A startup may therefore have dual-use exposure through:

  • hardware or components

  • software and encryption technology

  • technical data or know-how

  • sensors and navigation systems

  • advanced computing and semiconductors

  • quantum technologies

  • certain manufacturing technologies

  • cyber-surveillance technology

  • AI-enabled systems where the underlying capabilities fall within applicable controls

The EU control list is not static. The Commission updates Annex I periodically to reflect developments in strategic technologies and international export-control regimes. The 2025 update, for example, added or amended controls concerning quantum technology, semiconductor manufacturing equipment, advanced computing, additive manufacturing and other technologies. (Trade and Economic Security)

This is why a startup's regulatory position should be assessed against its actual technology and specifications, rather than against how the founders describe the company.

Being “dual-use” does not automatically mean your product is controlled

One of the most important distinctions for founders is between commercial dual-use potential and legal export-control classification.

A technology can have both civilian and defence applications without automatically being listed as a controlled dual-use item.

Conversely, a company that thinks of itself as purely civilian may develop software, hardware or technology that falls within the EU control regime.

Under Regulation (EU) 2021/821, exports of items listed in Annex I require authorisation. But the analysis does not necessarily end there. Certain non-listed items can also become subject to authorisation requirements depending on their destination, end-user or intended end-use under the Regulation's so-called catch-all controls. (Eur-Lex)

For a founder, this means that a simple question such as “Are we a dual-use startup?” is usually less useful than four more specific ones:

What exactly are we transferring?

How is the technology classified?

Who is receiving it and where?

What will it be used for?

Those questions determine whether export controls actually affect the transaction.

How do EU export controls apply to a dual-use startup?

For an EU-based dual-use startup, the main legal framework is Regulation (EU) 2021/821 on dual-use export controls.

The Regulation establishes controls over exports, brokering, technical assistance, transit and certain transfers of dual-use items. Annex I contains the common EU list of controlled dual-use items. (Eur-Lex)

If an item is listed in Annex I, export outside the EU generally requires an appropriate authorisation. Depending on the transaction, the available route may be an EU General Export Authorisation, national general authorisation, global authorisation or individual authorisation. (Trade and Economic Security)

However, classification is only the first layer.

The company also needs to consider the destination, end-user, end-use, sanctions and whether additional national controls apply. Regulation 2021/821 also permits controls in certain circumstances for items that are not listed in Annex I. (Eur-Lex)

This is particularly relevant to fast-moving technology businesses. A product roadmap can change faster than a startup's compliance processes. A new functionality, customer, integration or market can materially change the regulatory analysis.

LEGAL EXPERT INSIGHT – dr. Peter Merc, founder of Lemur Legal

“Founders often ask whether their company is ‘dual-use’, but that is not really the legal question. The analysis starts with the technology itself, then moves to the destination, end-user and intended use. A civilian business model does not automatically take a technology outside export-control rules.”

For companies that need to establish their position formally, this is where proper trade regulatory qualification becomes more useful than relying on a broad industry label.

Export does not just mean shipping hardware across a border

This is one of the areas where technology founders can underestimate export-control exposure.

Under Regulation 2021/821, an export can include the electronic transmission of controlled software or technology to a destination outside the EU. The Regulation specifically includes transmission by electronic means and making software or technology electronically available to persons outside the EU. (Eur-Lex)

That matters for companies whose most valuable asset is code or know-how rather than hardware.

A potential export-control issue can therefore arise before anyone ships a physical product. Depending on the circumstances and classification, access to software, technical documentation, controlled design information or other technology across borders may require analysis.

This makes export controls relevant to activities that startups often regard as routine, such as international pilots, technical partnerships, customer deployments, collaborative R&D or cross-border technology transfers.

The regulatory workflow therefore has to sit closer to product, sales and business development than many founders initially expect.

How does FDI screening affect deep-tech and dual-use startups?

Export controls govern the movement of sensitive items and technology. Foreign investment screening addresses a different question: who may acquire or exercise influence over strategically sensitive European companies and assets.

This has become considerably more relevant for dual-use founders.

In June 2026, the EU adopted Regulation (EU) 2026/1386, replacing the previous EU FDI screening framework. The new regime requires Member States to establish screening mechanisms and creates a common minimum scope for certain strategically sensitive investments. (Eur-Lex)

That minimum scope expressly includes EU targets that develop, produce or commercialise Annex I dual-use items. It also extends to certain semiconductor, quantum and artificial-intelligence technologies, among other strategic areas. (Eur-Lex)

For a startup, the practical consequence is significant.

Export-control exposure can affect not only sales and technology transfers but also fundraising, M&A and strategic investment. A foreign investor that looks commercially attractive may introduce an additional regulatory workstream if the startup operates in a sensitive technology sector.

The new Regulation also requires Member States to establish compliant national screening mechanisms by 17 January 2028. Existing national FDI regimes remain highly relevant in the meantime, so transaction-specific analysis continues to depend on the jurisdictions involved. (Eur-Lex)

This is one reason why export-control and FDI exposure should be considered during investment readiness reviews, rather than discovered after an investor has already entered due diligence.

Do dual-use startups need an export-control compliance programme?

Not every early-stage startup needs the compliance infrastructure of a multinational defence contractor.

But once a company repeatedly handles potentially controlled technology, international customers or sensitive destinations, relying on founders to remember the rules transaction by transaction becomes increasingly risky.

The European Commission's guidance on Internal Compliance Programmes identifies seven core areas for effective dual-use compliance: management commitment, clear responsibilities and resources, training, transaction screening, review and corrective measures, recordkeeping, and physical and information security. (Eur-Lex)

For a startup, proportionality matters. The compliance framework should reflect the company's size, products, markets, customers and risk profile.

The objective is not bureaucracy for its own sake. It is to create a repeatable answer to questions such as:

Is the product or technology controlled? Has the destination been checked? Has the customer and end-user been screened? Is an authorisation required? Who approves the transfer? What evidence is retained?

Once those questions become part of an operational workflow, export control is significantly easier to manage as the company scales.

Common mistakes dual-use founders make

The first mistake is assuming that having civilian customers means export controls do not apply. Legal classification is based on the controlled technology and transaction, not simply the company's branding.

The second is checking the product once and treating classification as permanent. Control lists evolve and products change. The EU's Annex I is updated periodically precisely because strategic technologies continue to develop. (Trade and Economic Security)

The third is looking only at physical exports. For software and technology businesses, electronic transfers can also fall within the export definition. (Eur-Lex)

The fourth is waiting until a shipment or investment round is already underway. Export-control, sanctions and FDI questions can surface during customer due diligence, accelerator applications, defence procurement, fundraising or M&A.

Finally, founders sometimes assume that appearing in a defence accelerator such as NATO DIANA automatically determines their legal status as a dual-use company. It does not. Accelerator eligibility and export-control classification are separate questions.

The commercial ecosystem around dual-use technology is expanding, but access to defence customers, investors and public programmes does not replace regulatory analysis.

What should a dual-use founder do first?

The best starting point is not to build a complex compliance function immediately. It is to establish whether the company actually has regulatory exposure.

Start with the product and underlying technology. Determine whether hardware, software, technical data or know-how falls within applicable control lists. Then map the countries, customers, partners and use cases involved.

If the technology is potentially controlled, determine the appropriate authorisation route before the relevant transfer takes place. For recurring activity, build the decision process into the company's operational workflow.

The same analysis should be revisited before entering a sensitive jurisdiction, transferring technology internationally, accepting a strategic investor or entering a major defence or dual-use programme.

A dual-use startup can benefit from access to both civilian and defence markets, but operating across those markets also creates a more complex regulatory perimeter. The companies that handle it well do not treat compliance as something to solve after the commercial decision has already been made. They understand the regulatory position early enough for it to inform that decision.

For founders building in defence and dual-use technology, Lemur Legal's approach is to begin with classification, move into transaction and investment readiness, and then build proportionate compliance processes where the business actually needs them.

Have a question like this? Book a consultation