Bosch to Pay $36 Million to Settle US Charges Over Unlicensed Huawei Shipments

German engineering and technology giant Robert Bosch GmbH has agreed to pay a $36.18 million civil penalty to the U.S. government to resolve charges that it made over 100 unauthorized shipments of technology to China’s Huawei Technologies Co. The settlement, announced by the Department of Commerce this week, addresses violations of U.S. export controls that occurred over a four-year period.

According to the settlement agreement with the Commerce Department’s Bureau of Industry and Security (BIS), the violations involved shipments of sensor products and automotive software valued at more than $72.4 million. The unauthorized exports to Huawei and its affiliates took place between September 16, 2020, and September 26, 2024. The products included Micro-Electro-Mechanical Systems (MEMS) sensors, which have broad commercial applications in smartphones, wearable technology, and automobiles.

The case underscores the extensive reach of U.S. export regulations. Although Bosch is a German company and the shipments were conducted by its non-U.S. subsidiaries, the transactions fell under American jurisdiction. The U.S. government placed Huawei on its Entity List in 2019, a move that requires companies to obtain a specific license from BIS before exporting certain U.S.-origin technology or products to the Chinese telecommunications firm. The regulations, particularly the foreign direct product (FDP) rule, extend to items made outside the U.S. if they are produced using certain U.S. technology or software.

Two Bosch subsidiaries, Bosch Sensortec GmbH and ETAS GmbH, were identified as having made the shipments. According to BIS, Bosch’s compliance failures included an instance where trade compliance officials incorrectly determined that the FDP rule applied only to physical goods and not to software. This misinterpretation led to the unlicensed export of automotive software to Huawei.

In a parallel action, the Department of Justice (DOJ) announced it would decline to prosecute Bosch criminally. This decision marks the first-ever corporate declination issued by the DOJ’s National Security Division under its updated Corporate Enforcement Policy. The leniency was granted because Bosch voluntarily self-disclosed the potential violations to U.S. authorities, cooperated fully with the subsequent investigation, and agreed to remedial measures.

As part of the resolution, Bosch will disgorge $11.43 million in pre-tax profits earned from the illegal sales. The financial penalties are structured between the two government agencies. The DOJ is crediting a portion of the disgorgement toward the BIS penalty, and BIS is suspending about $3.6 million of its penalty as a credit for the disgorgement paid to the DOJ. Bosch is required to pay approximately $32.5 million of the civil penalty to BIS within 30 days.

The settlement serves as a potent reminder for multinational corporations that U.S. export controls can apply even when transactions do not directly touch American soil. The case against Bosch highlights that the regulations are not limited to high-profile semiconductor technology but also cover a wide range of components and software that might be integrated into products destined for restricted entities.

For companies operating complex global supply chains, the Bosch settlement is a cautionary tale. The penalty, while significant, was mitigated by the company's decision to self-report. Had the violations been discovered by U.S. authorities first, the consequences, including potential criminal prosecution and a complete denial of export privileges, could have been far more severe.

In our experience, the most dangerous compliance failures are not born from deliberate attempts to evade rules, but from misinterpretations of an increasingly complex global regulatory web. The Bosch case is a perfect example; a compliance team made an incorrect judgment about whether software was covered by the foreign direct product rule, a mistake that ultimately cost the company tens of millions of dollars. For small and mid-sized businesses, whose compliance departments may be small or non-existent, the risk is even greater. A single misstep in navigating U.S. extraterritorial regulations can have crippling financial and operational consequences. This is precisely why robust financial risk management is not a luxury but a necessity for any company with international suppliers or customers. C&S Finance Group LLC helps clients build and audit these essential compliance frameworks to protect them from such unforeseen liabilities. To ensure your business is not exposed, contact us at csfinancegroup.com.

Moving forward, the resolution is expected to send a clear message throughout the technology and manufacturing sectors. U.S. authorities have signaled that they will continue to aggressively enforce export controls, particularly those related to national security and entities in China. The Bosch case provides a clear blueprint for other companies that may uncover their own violations: prompt self-disclosure and full cooperation can significantly reduce penalties and avert criminal charges.