The Permanent Emergency: How Security Exceptions Became the Norm in Digital Trade
Buried in virtually every trade agreement is a clause that says, in effect: none of this applies if national security is at stake. These security exceptions such as GATT art XXI, GATS art XIVbis, and their many regional equivalents, are the escape hatches of the international trading system. For decades they sat unused. Governments treated them the way nuclear powers treat their arsenals: too dangerous to deploy, too important to remove.[1]
That restraint is loosening. In the space of a few years, “security” has become the go-to justification for an expanding range of trade measures, from semiconductor export controls to data localisation mandates to investment screening of tech acquisitions.[2] The question is no longer whether states will invoke security to restrict digital trade, but how often, how broadly and with what consequences for the economies that depend on imported technology to function.
The last resort clause
For most of the GATT/WTO era, invoking the security exception was considered a step too far. The logic was that if one country starts claiming “security” to justify trade restrictions, others will follow, and the whole system unravels. So there was an unspoken understanding to leave art XXI alone.
That changed in 2019. When a WTO panel finally ruled on the security exception in Russia — Measures Concerning Traffic in Transit (DS512), it established that “emergency in international relations” is something a panel can actually review and it is not simply whatever the invoking state says it is.[3] A few years later, panels rejected the U.S. invocation of security to justify steel and aluminium tariffs in the Section 232 disputes (DS556), reinforcing the principle.[4]
But here is the paradox. The fact that panels started scrutinising security claims did not discourage states from making them. If anything, it accelerated the trend, because negotiators responded by writing their preferred version of the exception directly into new trade agreements, often in self-judging form that puts the clause beyond challenge.[5] The most notable regional example is RCEP art 12.15.3(b), which renders a party’s essential-security measures immune from dispute by its own text.[6] The result is a proliferation of security exceptions not despite adjudication, but in reaction to it.
The trend is quantifiable. The TAPED dataset at the University of Lucerne has coded the provisions of 495 preferential trade agreements.[7] Of those, 170 now carry a security exception specifically applicable to digital trade. Among Asia-Pacific agreements, 116 of 248 include one. And among those signed since 2016, the number is 65 out of 96 — roughly two in every three.
Look at the red line. In the early 2000s, it barely registers. By 2018, the year the CPTPP was signed, it passes 40 per cent. By 2020, when RCEP entered the picture, it crosses 60. In recent years it hovers between 70 and 80 per cent. The security exception has gone from a clause nobody used to one that nobody leaves out.
Security is not the only escape hatch
An important caveat: security exceptions are not the only way governments justify restrictive digital trade measures, and in practice they are often not even the first. The general exceptions such as GATT art XX and GATS art XIV, provide broader and more frequently invoked cover for measures aimed at privacy, public order, consumer protection and compliance with domestic laws.[8] A data localisation requirement, for instance, is far more likely to be defended as necessary for the protection of personal data under a general exception privacy limb than as a security measure under art XXI.
This matters for two reasons. First, it means the numbers in the chart above actually understate the total policy space available to restrict digital trade. The security exception is the most dramatic escape hatch, but the general exceptions are easier to invoke and they appear in virtually every trade agreement ever signed. Second, the two families of exceptions interact. The recent drafting trend of adding express security carve-outs to digital trade chapters gives governments a second, more deferential shelter on top of the general exceptions they already hold.[9] A government defending a data measure now has the option of running two arguments in sequence: first, that the measure is a legitimate privacy or public-order regulation under the general exception; and if that fails, that it is necessary for essential security under the self-judging carve-out. The layering of exceptions widens the available policy space while the access commitments sitting underneath them remain thin.
The gap between restriction and access
The spread of security exceptions would be less concerning if the commitments they sit on top of had kept up. They have not, and the gap between the two tells a story worth paying attention to.
Consider what the data shows for Asia-Pacific agreements signed over the last decade. The security exception, the provision that lets a government override its digital trade promises, appears in 68 per cent of them. But a binding commitment to allow free cross-border data flows? That shows up in only 38 per cent. A binding ban on data localisation requirements? 36 per cent. Binding protection for source code? Just 26 per cent.
Put simply: if a government wants to restrict digital trade on security grounds, it can find legal cover in two out of three recent agreements. If a business or trading partner wants a binding guarantee of access, they will find one in fewer than two out of five.
This is not a pattern unique to one dataset. Independent coding from the World Bank’s Deep Trade Agreements database tells the same story from a different angle.[10] Across 204 Asia-Pacific agreements, the provisions that protect, such as export controls, services liberalisation, intellectual property, are legally enforceable 93 to 98 per cent of the time. The provisions that promote technology sharing, such as research cooperation, innovation policy, data protection cooperation, are enforceable only 6 to 27 per cent of the time. That leaves us with the restrictions as law and the commitments to share as suggestions.
Why it matters
This gap between restriction and access has real consequences, and they fall hardest on the economies that can least afford them.
Think about what it means for developing and least developed countries in the Asia-Pacific region. Their government payroll, health records and disaster communications all run on a foreign cloud platform, and their sole submarine cable connects it to the internet. That country’s trade agreements guarantee the right to invoke security exceptions, and their technology suppliers are not even bound to provide the services they depend on. Therefore, trade agreements do not guarantee that country continued access to the services it depends on when the next cyclone hits or the next round of export controls tightens.
When the Hunga Tonga eruption severed Tonga’s submarine cable in January 2022, restoring connectivity required satellite capacity, network equipment and cloud migration — every one of which crosses a border governed by these agreements.[11] At no point did any trade instrument give Tonga a right to expedited access. Everything was discretionary. The trade architecture, in other words, has plenty of tools for saying no and very few for guaranteeing yes.
The conceptual drift from territorial security toward economic security only deepens the problem.[12] When semiconductor supply chains, cloud infrastructure and AI capabilities are all framed as essential security interests, the range of measures that can shelter under the exception expands to cover the subject matter of innovation trade itself. Whether “emergency in international relations” should stretch to encompass competitive technological rivalry is a question the jurisprudence has only begun to address[13] — but negotiators are not waiting for the answer. They are writing it into treaty text.
I have written about this broader dynamic in the context of the 2025 US tariffs, and it connects to the questions about data governance and sovereignty that run through the digital trade space. A recent restriction on the availability of Anthropic’s latest model in restricted-tier jurisdictions further develops the point.[14] This is a direct allocation of who may access a technology, justified on security grounds, with no sunset clause and no multilateral discipline. For any economy in the Asia-Pacific hoping to use frontier AI for public health, disaster preparedness or agricultural extension, the message is straightforward. Access depends on which tier you fall into, and you have no seat at the table where the tiers are drawn.
The normalisation of emergency in trade governance is more than a drafting trend. It is a structural reallocation of who gets access to technology and on what terms. And at the moment, the architecture is tilted decisively in favour of those who already have it.
References
Ji Yeong Yoo and Dukgeun Ahn “Security Exceptions in the WTO System: Bridge or Bottle-Neck for Trade and Security?” (2016) 19 JIEL 417 at 418–424 <doi:10.1093/jiel/jgw049>. ↩︎
Wolfgang Weiß “Interpreting Essential Security Exceptions in WTO Law in View of Economic Security Interests” in Karolina Milewicz and James Hollway (eds) Yearbook of International Economic Law (Springer, Berlin, 2020) 255 at 255 <doi:10.1007/978-3-030-34588-4_12>; Youyou Jiang “Defining the Boundaries: WTO National Security Exceptions in the US-China Unilateral Trade Sanctions” (2025) 18 JEAIL 299 at 301–302 <doi:10.14330/jeail.2025.18.2.03>; Umair H Ghori “Tussling Titans: The US-China Trade Wars and the Role of Export Controls” in Umair H Ghori Trade Wars and the Role of Export Controls (Edward Elgar, Cheltenham, 2023) 230 at 231, 305 <doi:10.4337/9781800889828.00014>. ↩︎
Russia — Measures Concerning Traffic in Transit WT/DS512/R, 5 April 2019 (Report of the Panel) at [7.71]–[7.77]. ↩︎
United States — Certain Measures on Steel and Aluminium Products WT/DS556/R, 9 December 2022 (Report of the Panel). ↩︎
Tania Voon and Mira Burri “Security Exceptions (Including Cybersecurity)” in The Cambridge Companion to World Trade Law (Cambridge University Press, 2026) 413 <doi:10.1017/9781009490146.020>, noting that “the security exceptions have played an important role in influencing the drafting of many PTAs” and that “in other agreements the WTO exceptions are essentially replicated or adopted with modifications”. ↩︎
Regional Comprehensive Economic Partnership Agreement (signed 15 November 2020, entered into force 1 January 2022), art 12.15.3(b). For analysis see Thomas Streinz “RCEP’s Contribution to Global Data Governance” (2021) Afronomicslaw <doi: 10.2139/ssrn.3826217>, observing that under RCEP parties “retain even greater leeway with regard to measures they consider necessary for the protection of ‘essential security interests’” and that “[s]uch measures are protected from other parties’ scrutiny altogether”. ↩︎
Mira Burri and Rodrigo Polanco “Digital Trade Provisions in Preferential Trade Agreements: Introducing a New Dataset” (2020) 23 JIEL 187 <doi:10.1093/jiel/jgz044>. Data in this post are drawn from TAPED version of 9 November 2025 and the World Bank Deep Trade Agreements database. ↩︎
Neha Mishra “Privacy, Cybersecurity, and GATS Article XIV: A New Frontier for Trade and Internet Regulation” (2020) 19 WTR 341 <doi:10.1017/S1474745619000120>; Shin-yi Peng “Digital Economy and National Security: Contextualizing Cybersecurity-Related Exceptions” (2023) 117 AJIL Unbound 122 <doi:10.1017/aju.2023.18>. ↩︎
Mira Burri and Kholofelo Kugler “Regulatory Autonomy in Digital Trade Agreements” (2024) 27 JIEL 397 at 405 <doi:10.1093/jiel/jgae025>, examining how “carve-outs, transition periods, the right to regulate, and exception clauses” provide “enhanced legal certainty and preserve policy space” in digital trade chapters. ↩︎
Aaditya Mattoo, Nadia Rocha and Michele Ruta (eds) Handbook of Deep Trade Agreements (World Bank, Washington DC, 2020) <doi:10.1596/978-1-4648-1539-3>. ↩︎
“Tonga’s undersea cable could take weeks to repair” (18 January 2022) Radio New Zealand <www.rnz.co.nz>. ↩︎
Olga Hrynkiv “Export Controls and Securitization of Economic Policy: Comparative Analysis of the Practice of the United States, the European Union, China, and Russia” (2022) 56 JWT 4 <doi:10.54648/trad2022026>, arguing that export controls now “go beyond conventional non-proliferation purposes to address economic security, technological supremacy, and human rights concerns” and observing “the increased convergence of economics and national security” manifesting in “the re-emergence of geoeconomic statecraft”; also see Weiß, above n 2. ↩︎
Panagiotis Delimatsis and Olga Hrynkiv “Sovereign Investors and National Security Exceptions in WTO and Investment Law” in Panagiotis Delimatsis, Georgios Dimitropoulos and Anastasios Gourgourinis (eds) State Capitalism and International Investment Law (Hart Publishing, Oxford, 2023) <doi:10.5040/9781509963003.ch-010>, identifying three forms of security exception — WTO-style good-faith review, full adjudicator scrutiny, and expressly self-judging — and noting that the scope of “essential security interests” remains contested. On the meaning of “emergency in international relations” see also Shin-yi Peng, above n 8, at 125, observing that it must be “at least comparable in its gravity or severity to a war”; Emmanuel Kolawole Oke “War, Armed Conflict, and the Security Exception in the TRIPS Agreement” (2024) IPQ 206 at 206–235 <uk.westlaw.com>. ↩︎
Francesco Bailo “Why the US government shut down Anthropic’s latest Claude AI model” (15 June 2026) The Conversation <theconversation.com>, reporting that an export control directive for Anthropic’s Fable and Mythos models “highlights the chaotic, fast-changing state of AI regulation”. ↩︎