Chip smuggling and export-control evasion refers to the channels through which advanced AI accelerators and semiconductor manufacturing equipment reach sanctioned Chinese end-users despite US export controls. Those controls are administered primarily by the Bureau of Industry and Security (BIS) through the Export Administration Regulations (EAR). Public evidence documents controlled items reaching restricted buyers via transshipment hubs, shell companies, diverted intermediaries, and insider exfiltration. The contested questions are how large the leakage is, whether it materially undermines the policy, and what enforcement capacity can do about it.
For the policy architecture this evasion targets, see Export Controls (AI); for the underlying chokepoint map, see Semiconductor Supply Chain.
Documented channels
Transshipment hubs
Smuggling routes route controlled GPUs through third countries before onward shipment to Chinese end-users.
Singapore is one of the most-cited hubs. Nvidia's Singapore-booked revenue rose from roughly 9% to roughly 22% of global sales in 2023–2024 (company disclosures), a fraction larger than plausible Singapore-destination demand, while downstream end-use auditing is limited. US and Singaporean authorities have opened investigations into a network of Singapore entities reshipping GPUs onward, documented in US DOJ indictments in 2024–2025. Malaysia plays a similar role; several cases filed by Singaporean prosecutors reference Malaysian onward routes. The United Arab Emirates has historically functioned as an intermediary for dual-use technology flows to sanctioned buyers; the 2024 G42 divestment from Chinese holdings, undertaken as a condition of a Microsoft investment, was partly a response to this pattern. Hong Kong is a long-standing transshipment hub, and Entity-List expansion has repeatedly targeted Hong Kong front companies.
US prosecutors on May 8, 2026 identified Bangkok-based OBON Corp., referred to only as "Company-1" in a March 2026 indictment of Super Micro Computer's co-founder, as the Southeast Asian intermediary suspected of helping smuggle billions of dollars of Nvidia AI servers to China, with Alibaba among the end customers. The identification, dated May 9, 2026 in the developments log, was the first public naming of the Thailand-routed pipeline, alongside the Singapore-onward and UAE-mediated routes (Source: bloomberg.com). Whether the OBON identification leads to at least 2 DOJ, BIS, or Treasury OFAC enforcement actions against the broader broker network by mid-2027, or remains one isolated identification, is unresolved.
The Thailand route surfaced again in July 2026: OSTP Director Michael Kratsios said on July 22 that Moonshot AI acquired GB300-equipped servers and accessed the banned Nvidia chips in Thailand, likely for training, and the Bureau of Industry and Security confirmed a formal investigation into whether Chinese firms including Moonshot are accessing advanced U.S. AI chips, with Entity List designation a possible outcome (Source: bloomberg.com; theinformation.com).
Taiwan as an origin-side enforcement venue
Enforcement has also opened at the point of manufacture rather than the point of transshipment. Taiwan's Keelung District Prosecutors Office said on July 28, 2026 that it had detained a suspect surnamed Chang — identified by Mirror Media and Bloomberg as an Nvidia employee — on suspicion of forgery and breach of trust over AI servers exported to China in violation of U.S. export controls. Investigators searched his home and workplace, including a desk at Nvidia's Taipei office, on July 24, 2026. Seven people are in custody in an investigation opened in May 2026 centring on roughly 50 falsely documented Super Micro servers; the prosecutors' statement does not accuse Nvidia of wrongdoing, and Nvidia said smuggling is a "nonstarter" (Source: qz.com; forbes.com). The case extends the crackdown that began with the three detentions of May 2026, in which Jensen Huang publicly urged Super Micro to tighten compliance, and moves the exposure from an OEM partner's paperwork to a vendor's own staff.
Shell companies and reshell cycles
Chinese buyers set up US or third-country shell companies that order GPUs, re-export or smuggle them, and dissolve before end-use verification. When BIS lists a shell, the buyer spins up a new one, producing a pattern of enforcement followed by replacement. The Entity List grew substantially across 2022–2025 partly in response.
Insider theft and IP exfiltration
Linwei (Leon) Ding, a former Google engineer, was indicted in March 2024 by the DOJ for theft of approximately 500 files of Google TPU architecture IP for transfer to Chinese firms, one of the highest-profile AI-related trade-secret cases. The DOJ has separately indicted ex-ASML, ex-Applied Materials, and ex-Lam Research employees for IP transfer to Chinese entities over 2022–2024. See CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary) for the case roundup.
TSMC–Huawei die pipeline
Following BIS expansion of foreign direct product rule controls on Huawei, TSMC was found in late 2024 to have shipped approximately 2 million advanced dies fabricated to Huawei specification via intermediaries including Sophgo, in violation of export controls as interpreted by BIS. Gregory Allen of CSIS documented the pattern in detail. TSMC halted the relationships and disclosed to BIS. The episode illustrated how even a Tier-1 ally's supplier can leak controlled items at industrial scale.
Estimated leakage volume
The total volume of smuggled compute is contested. Allen (CSIS) and SemiAnalysis estimates suggest material volumes, with hundreds of thousands of restricted GPU-equivalents annually reaching Chinese buyers by various channels; the TSMC–Huawei episode alone involved approximately 2 million dies. Some US officials argue the controls remain substantially binding, contending that China's frontier training clusters operate but at lower effective compute than they would without controls and that the gap is real (Source: Raw Sources/SemiAnalysis - Huawei Ascend Production Ramp.md). Toby Ord and others warn that long-horizon evasion and domestic substitution (SMIC plus CXMT) may erode the policy effect by 2028–2030 even if it is binding in the near term. These readings are not mutually exclusive: controls may be partially effective now while evasion is substantial, with the long-run question being whether substitution outpaces tightening.
Epoch AI on May 8, 2026 published what it described as the first comprehensive published estimate of the volume of advanced-AI compute smuggled into China through the end of 2025: a range of 290,000 to 1.6 million Nvidia H100-equivalents, with a median of approximately 660,000, equivalent to roughly 3% of global compute and comparable to xAI's stockpile. The estimate aggregates indictment evidence (Supermicro $2.5B, Megaspeed approximately 50,000 chips, Hao Global) plus gray-market resale evidence under a 10–80% detection-rate range. It is the first attempt at numeric calibration of total smuggling volume against the 1.6× upper-bound and 0.3× lower-bound brackets that prior CSIS and Epoch commentary had referenced qualitatively (Source: epoch.ai). Whether the median estimate (660,000 H100-equivalents through 2025; range 290,000–1.6 million) holds up in subsequent independent estimates, or proves to be the high outlier, is not yet settled. Epoch's own framing anticipates replication; as of mid-2026 no independent RAND, CSIS, IISS, or academic estimate within a ±20% band (roughly 528,000–792,000 H100-equivalents through 2025) had confirmed or rebutted the figure (Source: epoch.ai).
BIS enforcement gap
Per Gregory Allen (CSIS) and multiple congressional testimonies over 2023–2025, BIS export enforcement is under-resourced relative to the scope of the EAR regime. BIS export-enforcement headcount is approximately 600 total staff, of which a small fraction works on advanced-chip cases, for the entire federal enforcement of the EAR. By comparison, the US Treasury's OFAC has roughly double the enforcement headcount and a narrower mandate. The FY2025 and FY2026 budget requests sought expansion but faced appropriation headwinds. BIS on-site end-use verification checks depend on cooperation from host governments, are episodic, and cover a small fraction of shipments. Allen's recurring position is that the controls themselves are well-designed while the enforcement apparatus is chronically under-resourced relative to the scale of the targeted trade. See CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary). Whether BIS obtains a material enforcement-headcount expansion in any FY2026–FY2028 appropriation is unresolved.
Policy responses
BIS has continuously expanded the Entity List with shell companies, transshipment intermediaries, and newly identified front entities. As of 2025–2026 the list includes hundreds of AI-relevant Chinese entities plus dozens of third-country facilitators, and it grows faster than evasion schemes are retired.
The Foreign Direct Product Rule (FDPR), introduced in 2022 and expanded in 2023 and 2024, extends US jurisdiction to foreign-made items using US technology and is the legal basis for the Huawei die enforcement. It is the most far-reaching extraterritorial tool but creates friction with allies.
The Executive Order 14110 — Safe, Secure, and Trustworthy AI-era dual-use foundation-model reporting has been rolled back under Executive Order 14365 — Ensuring a National Policy Framework for AI and the America's AI Action Plan, but training-compute disclosure and end-use reporting remain active for certain items.
A parallel channel is access to US cloud AI training compute, in which evasion occurs by renting rather than buying. A Commerce NPRM in January 2024 proposed "know-your-customer" rules on foreign access to US cloud AI training compute; finalization has stretched across 2024–2026. Whether the cloud-compute KYC rule finalizes and binds on actual training runs is unresolved, with BIS proposed rulemaking pointing toward a final Federal Register publication of KYC requirements on cloud rental of restricted compute. Some commentary anticipates further tightening of the regime in 2026, including compute caps on cloud-rented Nvidia chips abroad; as of mid-2026 no BIS rule, EO, or DOC guidance restricting US cloud providers from renting H100/H200/B200/Blackwell-class compute to China-headquartered customers above a defined threshold had been issued, with the proposed rulemaking pointing toward a final Federal Register publication targeted before December 31, 2026.
Allied coordination on semiconductor manufacturing equipment controls among the Netherlands, Japan, and the US works reasonably well. Extending that coordination to downstream packaging, high-bandwidth memory (HBM), and cloud is more contested. See Semiconductor Supply Chain and Export Controls (AI).
On May 26, 2026 the Senate passed the Stop Stealing Our Chips Act (Rounds R-SD and Warner D-VA), establishing a BIS whistleblower-incentive program for reporting illegal exports of advanced AI semiconductors. The act is the first concrete legislative attempt to address the enforcement-capacity gap by crowdsourcing diversion detection through a bounty structure modeled on the SEC and IRS whistleblower regimes, rather than by writing new controls. House action is pending (Source: insideaipolicy.com).
Relationships
- depends-on: Export Controls (AI), Semiconductor Supply Chain
- supports: AI and National Security, AI Race Dynamics
- related: Bureau of Industry and Security (BIS), Huawei — Ascend AI Accelerators, Nvidia & TSMC — AI Compute Infrastructure, SMIC — Semiconductor Manufacturing International Corporation, Center for Security and Emerging Technology (CSET), Dylan Patel
Wiki sources
- CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary) — Gregory Allen enforcement analysis, TSMC–Huawei die pipeline, Linwei Ding case.
- CSIS — DeepSeek, Huawei, Export Controls, and the Future of the U.S.-China AI Race (Allen, March 2025) — follow-on analysis of DeepSeek and Huawei circumvention.
- (Source: Raw Sources/SemiAnalysis - Huawei Ascend Production Ramp.md) — Chinese alternative stack detail.
- Bureau of Industry and Security (BIS) — agency page.