Tech | Hex

Business Intelligence | Market Analysis

Field Definitions Before Counts: Writing Export-Control Exposure for a Technical Audience

Capstone coursework · concept draft · 14 September 2026

What this is. A graded assignment from my M.S. in Business Intelligence at Full Sail University, published as a portfolio item showing method. The task was to have a language model draft a two-page memorandum explaining a Week 1 risk finding to the technical stakeholders at the company, then evaluate that draft and make no fewer than five significant revisions under tracked changes, with a comment on each explaining the reasoning.

What this is not. It is not a client deliverable and not a real proposal. The memorandum below was never sent to NVIDIA. No engagement was ever offered, discussed, or contemplated. The recipients are generic engineering functions, not real people. Tech Hex is an independent practice and is not affiliated with, endorsed by, sponsored by, or engaged by NVIDIA Corporation.

What it is grounded in. Every factual claim traces to a public, verifiable identifier: a bill number, an official bill-status record, a published client alert, or the company’s own quarterly release. Each is linked inline, so any claim can be checked at its source rather than taken on trust. Figures are labeled observed, modeled, or hypothetical. Author: Matthew G. Williams, ORCID 0009-0000-5068-7849.

The audience changed, and that changes the document

Week 2 addressed four operational functions at NVIDIA and told them what to do. Week 3 addresses four engineering functions and asks them what is possible. That is a larger change than it sounds, because a technical audience is not a harder or softer version of an operational one. It is a different reader running a different test.

An operational reader asks whether the direction is clear and who owns it. A technical reader asks whether the premise survives contact with the system. Hand that reader a number without its inputs and the reader stops at the number. Hand them a verb like monitor with no control named, and there is nothing to cost, schedule, or refuse.

So the memorandum carries its arithmetic in line, names the three controls by the names their owners use, and asks for a schema rather than a total.

Where the exposure sits

Data center revenue was $89.0 billion of $96.2 billion in the second quarter of fiscal 2027 (NVIDIA Corporation, 2026), which recomputes to 92.5 percent. Two versions of the Remote Access Security Act sit in the Senate Committee on Banking, Housing, and Urban Affairs, and neither has moved since 13 January 2026.

The control those bills would create does not govern a product. It governs a record, and no such record exists. That is the whole argument: remote access to a controlled item is not a dimension the platform emits, so the exposure cannot be counted, and an exposure that has never been counted cannot be scoped on somebody else’s deadline.

A schema difference, not a policy nuance

Read the two bills as predicates over a record rather than as policy language, and the gap between them stops being a matter of degree. Each predicate demands specific fields, and the House predicate is the wider one. Nine fields separate them, and two of the nine are where the texts disagree outright: the House text needs a knowledge state that the Senate text never mentions, and the Senate text needs an origin outside the United States that the House text does not ask for.

Field the record must carry H.R. 2683, passed the House S. 3519, same committee
Principal identity required required
Nationality basis any foreign person designated-list lookup
Access channel any network connection cloud infrastructure service only
Origin relative to the item required, a location other than where the item sits required, a location other than where the item sits
Origin outside the United States not required, no such limit applies required
Knowledge state of the access required, purposeful, knowing, reckless, or negligent not in the definition, no scienter element
Use or risk characterization the Secretary’s serious-risk determination enumerated categories only
Controlled-item class required required
Record retention horizon indefinite, no sunset 10 years from enactment
Table 1. Both columns are observed, read from the bill texts themselves: H.R. 2683 §2(1) and S. 3519 §2(a). Status drawn from the official bill-status data sets, re-read on 14 September 2026. Whether the platform emits any of these fields today is a separate column, deliberately absent, because it cannot be established from outside the company.

The consequence is asymmetric, and it is the reason the request is scoped the way it is. A population counted to the Senate predicate cannot be widened to the House predicate afterward, because the sessions outside the narrower predicate were never recorded in the first place. Counting to the wider predicate and filtering down is reversible. Counting to the narrower one and trying to widen it is a rebuild.

The fields are only half of the predicate. The other half is which access channels each text reaches at all, and there the two diverge further still. S. 3519 §2(a) restricts the covered channel to infrastructure as a service, as defined by NIST SP 800-145. H.R. 2683 §2(1) names no channel restriction whatsoever.

Access channel H.R. 2683 S. 3519
Cloud infrastructure service (IaaS) in scope in scope
Cloud service other than IaaS (PaaS, SaaS) in scope out of scope
Other network connection (VPN, private link) in scope out of scope
Remote administration or support session in scope out of scope
Storefront access without download interpretive out of scope
Provider’s own foreign national IT staff interpretive out of scope
Table 2. Channel scope, observed, read from the bill texts. Two channels are marked interpretive under the House text because its language reaches them while the standing BIS advisory opinions point the other way. Cross the nine fields of Table 1 against these six channels for both texts and the requirement map is 108 cells: 40 of them requirements, 16 of them cells the texts do not resolve, and one column, whether the platform emits the field today, that stays empty because it cannot be filled from outside the company.

The signals are already in the stack; the join is not

Outside counsel reviewing this legislation names the applicable controls as geo- and IP-based screening, identity and access management, and audit logging (Latham & Watkins, 2026, Practical Guidance). None of that is new build. All three exist already, for entitlement, abuse prevention, and support. What is missing is a join across those three that resolves to one record per arrangement, with a nationality basis attached to the principal and a controlled-item class attached to the object.

The absence of that record is not an oversight, and the first draft of the memorandum was wrong to imply that it was. BIS advisory opinions concluded that cloud providers do not need deemed export licenses for foreign national IT staff with access to export controlled data on a cloud network, and that a user who reaches software in a cloud storefront without downloading it has not received an export. The perimeter sits where it sits deliberately. The legislation would move it, and instrumentation for a perimeter that has not moved has never had a reason to exist. Conceding that is what buys the rest of the argument a hearing from people who have worked a deemed-export question before.

The memorandum, reproduced in full

This is the artifact the assignment turned on, so it is printed rather than described. What appears below is the revised text, after the eight tracked changes listed in the next section.

Memorandum · NVIDIA technical stakeholders · hypothetical, never sent

To: Data Center Platform Engineering; Cloud Partner Engineering (DGX Cloud and CSP integration); Security Engineering, Identity and Access Management; Trade Compliance Engineering
From: Matty Williams, Founder, Tech Hex <hex@techhex.press>
Date: 14 September 2026
Subject: Field definitions needed before a remote-access count can be taken


Bottom line. Two versions of the Remote Access Security Act sit in Senate Banking, and they do not define the same covered activity. Neither has moved since 13 January 2026. The request in this memo does not depend on either one being enacted. It depends on something already true: remote access to a controlled item is not a dimension the platform emits, so the exposure cannot be counted, and an uncounted exposure cannot be scoped on someone else’s deadline. I am asking Platform Engineering and Security Engineering for the field definitions that would make such a count possible, scoped to the House text, and for a range estimate of the work to emit them.

Why this reaches engineering and not only compliance. Data center revenue was 89.0 of 96.2 billion dollars in the second quarter of fiscal 2027, or 92.5 percent, recomputed here as 89.0 / 96.2 = 0.9252. The control that would govern remote access to those products is not a product control. It is a data-model question, and the data model belongs to this audience.

The difference between the two texts is a schema difference. H.R. 2683 passed the House 369 to 22 on 12 January 2026. It reaches any foreign person, over any network connection, with no geographic limit and no sunset. S. 3519 reaches a foreign person of concern, through cloud infrastructure service only, located outside the United States, against enumerated categories, with a ten-year sunset. A population counted to the Senate predicate cannot be widened to the House predicate later, because the sessions outside the narrower predicate were never recorded.

The signals are already in the stack. Geo- and IP-based screening, identity and access management, and audit logging all exist. What is missing is a join across those three that resolves to one record per arrangement, with a nationality basis attached to the principal and a controlled-item class attached to the object. The absence of that record is not an oversight; the deemed-export perimeter sits where it sits deliberately.

What I am asking for. Three things, and the first of them matters most:

  1. Field definitions. Principal identity, nationality basis and how it is established, access channel, origin region, controlled-item class, and session start and duration. These matter more than the number, because a count without them cannot be re-scoped.
  2. An arrangement count by region, scoped to the House predicate, for the trailing ninety days. No estimate is offered here, because none can be sourced.
  3. A work estimate for emitting those fields continuously, given as a range with the assumptions attached rather than as a single figure.

What I am not asking for. No new collection of end-customer identity beyond what entitlement already requires. No change to product behavior, retention policy, or customer-facing notice. If the count cannot be produced without one of those, that finding is more useful than the count and should come back as the answer.

What remains open. No probability is attached to either bill. This memo was prepared from public disclosure by an outside practice with no access to internal systems, which is why the count is requested and not estimated. If either text is enacted, the count will already be needed, and the comment window on a proposed rule is where that work has to be finished rather than started.


Matty Williams
Founder, Tech Hex
techhex.press
Signal over noise

Tech Hex is an independent practice and is not affiliated with, endorsed by, sponsored by, or engaged by NVIDIA Corporation. This memorandum is hypothetical and was never sent.

What the model drafted, and what I changed

The assignment required a language model to produce the first draft and no fewer than five significant revisions, each carrying a comment that explains it. There are eight. They are reproduced here because the revision is the part that shows judgement. The draft only shows fluency.

# What changed The draft said It now says Why
1 An unsourced magnitude “A large share of last quarter’s revenue came from the data center segment, so the stakes here are significant.” 92.5 percent, recomputed in line as 89.0 / 96.2 = 0.9252. A technical reader reproduces arithmetic before accepting a premise. It also removes an assertion standing in for evidence.
2 A fabricated count “My working assumption is that this is on the order of 10,000 arrangements.” No estimate is offered here, because none can be sourced. Nothing was behind the number. Presenting an invention as an estimate to the people who own the telemetry is the fastest available way to lose the room.
3 Operational carry-over “Revenue Planning should re-weight its three scenarios once the count arrives.” Deleted. This audience can neither act on scenario weighting nor check it. The assignment asks for detail not useful to technical readers to be omitted rather than restated.
4 An unassignable verb “What is missing is better monitoring of cloud resources.” A join across those three that resolves to one record per arrangement. “Monitoring” cannot be assigned, estimated, or refused. Naming the missing artifact gives an engineering lead something to cost.
5 The shape of the ask “I am asking for a count of remote-access arrangements.” The field definitions that make such a count possible, scoped to the House text. A count without its predicate cannot be re-scoped, which is the entire risk the memo is about.
6 A missing concession Nothing. The draft implied the gap was negligence. Added the deemed-export advisory-opinion history. Readers who have worked a deemed-export question know that history and would have stopped at the implication.
7 An asserted outcome “When the rule takes effect, the count will already be needed.” “If either text is enacted…”, plus the comment window as the fixed clock. No cited source publishes a probability. The conditional is honest, and the comment window restores the urgency without predicting a vote.
8 The subject line “Remote access under the Remote Access Security Act: implications for the data center platform.” “Field definitions needed before a remote-access count can be taken.” Chasen and Putnam (2012, Chapter 4) make the subject line decisive for whether a memo is read at all.

Two of the eight are the same failure wearing different clothes. The model produced a quantity with nothing behind it, and it asserted an outcome as scheduled rather than conditional. Both are fluent, both are plausible, and neither survives a reader who checks. That is the argument for keeping the markup rather than shipping a clean draft: a language model is a fast drafter and a poor witness, so every figure in the final document traces to a primary source that was opened while writing it.

How the figures were re-verified

  • Bill status, re-read rather than carried. Both GovInfo bill-status records were opened again on 14 September 2026. H.R. 2683 is unchanged since 13 January 2026, S. 3519 since 17 December 2025, and no markup has been noticed on either. A figure that was true last week is not a figure. It is a memory.
  • The revenue split, recomputed. 89.0 / 96.2 was divided again and returns 0.9252. Reproducing external arithmetic before building on it is a house rule, and it is cheap.
  • The bill texts, read rather than summarized. Both were read end to end rather than taken from a client alert, and that changed two rows of Table 1. H.R. 2683 §2(1) does carry a location test and does carry a scienter element. S. 3519 §2(a) carries two stacked location tests and no scienter element at all. An earlier version of this table said the House text had no location requirement. It does, and the row is corrected here rather than quietly left standing.
  • The tables are rendered from the data, not typed. Both tables above come from the same workbook that feeds the Power BI model, so the figures and the data cannot drift apart.
  • One correction to the Week 2 brief. That brief dates the NVIDIA release 27 August 2026. The newsroom page reads 26 August 2026. The earlier date is wrong and is corrected here rather than quietly carried forward.

What remains open

No probability is attached to either legislative outcome, because no cited source publishes one. Whether each field is emitted by the platform today cannot be established from outside the company at all. That is the column the memorandum requests, and it is the one no amount of public research will fill. Naming that limit is more useful than filling it with a number, and refusing to fill it is the single decision this assignment was really testing.

Earlier in this series: Two Bills, One Committee, the same finding written for an operational audience, and the Week 1 PESTLE analysis the whole series rests on.


Sources

Every entry links to the document itself.

  • Chasen, E. A., & Putnam, R. R. (2012). The manager’s communication toolbox (Chapter 4, “Write Effective Letters and Memorandums,” section “Writing Memos”). ASTD Press.
  • Latham & Watkins. (2026, March 20). What the Remote Access Security Act means for export controls compliance programs [Client alert]. lw.com
  • National Institute of Standards and Technology. (2011). The NIST definition of cloud computing (Special Publication 800-145). U.S. Department of Commerce.
  • NVIDIA Corporation. (2026, August 26). Financial results for second quarter fiscal 2027. NVIDIA Newsroom
  • Remote Access Security Act, H.R. 2683, 119th Cong. (2026). Bill text, PDF
  • Remote Access Security Act, S. 3519, 119th Cong. (2025). Bill text, PDF
  • U.S. Government Publishing Office. (2026). Bill status for H.R. 2683 and S. 3519, 119th Congress [Data sets]. GovInfo bulk data
  • Williams, M. (2026). Watch the rule that governs the data center line [Unpublished assignment 2.3, BIN650-O]. Full Sail University.

AI disclosure

The assignment required a language model to produce the first draft, so Claude (Anthropic) wrote it and I then revised it under tracked changes, eight times, with a comment recording the reason for each. Before drafting, Claude re-opened both bill-status records and NVIDIA’s quarterly release at my direction and recomputed 89.0 / 96.2; it also surfaced the date error I had carried in the Week 2 brief. I set the verification standard, judged what could be cited, wrote or rewrote every load-bearing sentence in the final text, and removed the two claims the draft invented. The judgement in the revision is mine, and so is the accountability for it.

© 2026 Matthew G. Williams · Tech Hex · ORCID 0009-0000-5068-7849. Published as a portfolio item from graduate coursework in the M.S. Business Intelligence program at Full Sail University. The memorandum reproduced here is hypothetical and was never sent.


Filed in

Discover more from Tech | Hex

Subscribe now to keep reading and get access to the full archive.

Continue reading