虎嗅

Bosch in Germany fined $47 million by the US for supplying goods to Huawei: Lessons on extraterritorial jurisdiction, corporate compliance, and CEP policies

原文:德国博世因向华为供货被美国罚了4700万美元:域外管辖权、企业合规选择与CEP政策启示

Summary of Key Points

In June 2026, the U.S. Department of Justice (DOJ) and the Bureau of International Trade (BIS) jointly imposed penalties on two subsidiaries of the German company Bosch Group, Bosch Automotive Electronics and ETAS. The companies were accused of exporting MEMS sensors and automotive safety software to Huawei without U.S. authorization from 2020 to 2024, with total transactions exceeding $70 million. Bosch avoided criminal prosecution by voluntarily disclosing the violations but was required to pay a fine of $36.18 million plus an additional $11.43 million in pre-tax profits (a total of approximately $47.61 million), and expanded its global trade compliance team from two members to 68. The key highlights of this case include the use of the Foreign Direct Product Rule (FDPR) by the U.S. to exercise long-arm jurisdiction, as well as the first application of a new corporate voluntary disclosure policy (CEP) in the area of national security, which serves as a significant warning for Chinese companies' export compliance.

Detailed Analysis

1. How Does the U.S. Regulate German Companies’ “Local Transactions”? – Through Long-Arm Jurisdiction Based on “Technological Origin”

Many people wonder how the U.S. can regulate German companies when their products are manufactured in Germany and sold to Chinese companies like Huawei, with no direct involvement of U.S. entities. The answer lies in the use of the Foreign Direct Product Rule (FDPR), which does not consider the location of production but focuses on the “technological origin” of the products or the equipment used in their manufacture. If a product is either a direct result of U.S.-controlled technology or software, or if the manufacturing equipment uses such technology, and the end-user is a company on the U.S. Entity List (such as Huawei), the U.S. has the authority to regulate it. Bosch made a common mistake by mistakenly assuming that the presence of less than 25% U.S.-made components meant it was exempt from regulation; this is a pitfall that many non-U.S. companies often fall for.

2. Why Did Bosch Voluntarily Admit Its Violations? – A Calculation of Costs and Benefits

Bosch’s decision to confess was not out of honesty but a strategic one, weighing the risks and benefits:

  • The Consequences of Defiance Would Be Severe: Bosch has significant business operations, assets, and dollar-denominated financial activities in the U.S. Criminal prosecution could result in hefty fines, imprisonment for executives, and loss of export rights. Moreover, third parties had previously warned Bosch about its violations, but it ignored them, increasing the likelihood of a criminal conviction.
  • The Benefits of Voluntary Disclosure: In March 2026, the U.S. introduced the CEP policy, which offers criminal immunity if four conditions are met: timely disclosure, full cooperation, proper remediation, and no serious circumstances. Bosch met these criteria by reporting the issues before internal investigations were completed, cooperating fully with authorities, and expanding its compliance team. Although it still faced civil penalties, it avoided the more severe consequences of a criminal conviction.

3. The First Application of CEP in National Security

The CEP policy was previously limited to certain departments within the DOJ but was expanded to all agencies in March 2026. Bosch became the first case to apply this policy under the National Security Directorate (NSD). This represents a significant change, as it provides companies with an opportunity to avoid criminal charges by admitting violations and paying civil fines.

  • The Importance of the Policy’s Scope: The term “no serious circumstances” is flexible and may vary depending on the context, such as whether the technology involved is related to advanced chips, AI, or dual-use applications. Therefore, not all situations are covered by this policy.

4. Lessons for Chinese Companies

This case offers three key lessons for Chinese companies:

  • Reverse Trace the Supply Chain: Companies should review their upstream suppliers to ensure that the equipment used in product manufacturing does not contain U.S.-owned technology and that suppliers do not supply products to entities on the U.S. Entity List.
  • Compliance Teams Must Be Competent: Bosch’s initial compliance team of two members was inadequate for managing complex regulations. Many Chinese companies struggling with export controls, sanctions, and customs issues often rely on one person to handle multiple tasks, which can lead to shortcomings in compliance efforts. Companies should invest more in specialized resources.
  • Pay Attention to Third-Party Warnings: Bosch ignored warnings about its violations, which could have led to even worse consequences. Chinese companies should promptly verify any such alerts and not take chances.
  • Understand the CEP Policy: For companies with past violations, voluntary disclosure may be a better option than waiting to be caught, but they need to assess whether their circumstances qualify for exemption.

5. The Significance of This Case as a Demonstration of U.S. Export Control Strategies

The Bosch case illustrates how the U.S. combines two tools: FDPR for long-arm jurisdiction over non-U.S. companies and CEP to encourage voluntary compliance, thereby reducing enforcement costs. It indicates that U.S. export controls are shifting from targeting specific companies directly to disrupting the supply chain upstream. Chinese companies must take export compliance more seriously to avoid becoming the next targets.

This case serves as a clear reminder of the new approach to U.S. export regulations and highlights the critical importance of compliance for businesses, as it can have a direct impact on their survival and success.