Start Free Trial
Home/Regulations/CBP Customs Regulations (19 CFR) — Regulatory Reference
Regulatory Reference
Logistics Federal (US) high

CBP Customs Regulations (19 CFR) — Regulatory Reference

Cross-border supply chain data — AutoPIL enforces cross_border_restrictions policy and maintains audit trail for import/export data access.

Key Provisions
  • 19 CFR Part 113 — bonds
  • 19 CFR Part 142 — entry process and ACE / ACAS
  • Recordkeeping under 19 USC § 1508 — five-year retention
  • C-TPAT (Customs-Trade Partnership Against Terrorism) supply chain security
How AutoPIL Enforces It
  • Cross-border restriction policy controls AI access to import/export data by destination
  • Audit chain supports five-year retention requirement under § 1508
  • Agent registry isolates broker, forwarder, and importer-of-record AI roles
Audit LogPolicy EngineSensitivity LabelsLineage
AutoPIL Policy IDs
LOG-CBP-1508-001Customs Record Retention for AI Access
LOG-CBP-CTPAT-001Supply Chain Security AI Controls
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does 19 CFR require for AI agents accessing import/export data?
19 CFR does not address AI agents directly, but its recordkeeping and entry requirements create clear obligations for any system that touches customs data. Under 19 USC § 1508, importers and brokers must retain entry records for five years — this applies regardless of whether a human or an AI agent queries, processes, or routes that data. 19 CFR Part 142 governs the entry process through ACE (Automated Commercial Environment), where data integrity and access accountability are core compliance requirements. Organizations deploying AI agents against customs filings, shipment manifests, or broker records need to demonstrate that every data access is logged, attributable, and retained for the full five-year period.
When does 19 CFR apply to AI deployments in logistics and supply chain?
19 CFR applies whenever an AI agent touches data that is subject to CBP jurisdiction — import entries, export filings, ACE/ACAS submissions, bonded warehouse records, or carrier manifests. This is not limited to agents that file with CBP directly. Any agent that reads, summarizes, routes, or makes decisions based on customs records is operating on regulated data. This includes demand forecasting models pulling historical entry data, broker automation tools parsing HTS classifications, and freight AI systems accessing shipment status from ACE. If the underlying data falls under 19 USC § 1508 retention requirements or C-TPAT supply chain security obligations, AI access to that data is within scope.
What is C-TPAT and how does it affect AI agent governance in supply chain?
C-TPAT (Customs-Trade Partnership Against Terrorism) is a voluntary CBP program that sets supply chain security standards for importers, brokers, carriers, and other trade partners. Certified members commit to documented access controls, internal audits, and partner vetting requirements across their supply chain. For AI deployments, C-TPAT requirements map directly to agent access control: who (or what agent) can access sensitive shipment data, under what conditions, and with what audit record. C-TPAT audits increasingly scrutinize IT and data access controls. An AI agent querying supplier records, carrier data, or cross-border shipment details without access governance creates a gap that can jeopardize C-TPAT certification status.
How does AutoPIL help with 19 CFR recordkeeping and customs compliance?
AutoPIL addresses the two primary 19 CFR compliance requirements for AI deployments. First, the tamper-evident audit log records every AI agent data access decision — policy applied, agent identity, data source, sensitivity level, and outcome — satisfying the five-year retention requirement under 19 USC § 1508 without relying on application-layer logging that can be altered. Second, the cross-border restrictions policy (policy ID LOG-CBP-1508-001) enforces destination-based access controls on import/export data before it enters the agent's context window. The agent registry isolates broker, forwarder, and importer-of-record roles so that each AI agent operates only within its authorized scope, which directly supports C-TPAT access control documentation requirements.
What are the enforcement risks under 19 CFR for companies using AI in customs operations?
CBP enforcement under 19 CFR carries civil and criminal penalties for recordkeeping failures, entry errors, and customs fraud — and liability does not diminish because an AI system was involved. Under 19 USC § 1508, failure to maintain required records can result in penalties up to the dutiable value of the merchandise. If an AI agent generates an incorrect entry or misroutes a shipment due to unauthorized access to incorrect data, the importer of record bears the customs liability. For C-TPAT certified companies, a documented access control failure — including inadequate controls over AI agent data access — can trigger suspension or removal from the program, disrupting expedited clearance benefits and damaging partner trust.
Covered Industries

19 CFR applies to any organization that imports, exports, or brokers goods across US borders — including the AI systems those organizations deploy against customs records, shipment data, and supply chain filings. For AI deployments, the key obligations are audit-quality recordkeeping under 19 USC § 1508 and access controls required for C-TPAT certification.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries