AI Policy Wiki
Dashboard

Export Controls (AI)

medium confidence · updated 2026-08-17

US restrictions on adversary access to advanced chips, AI technology, and capital — effectiveness depends heavily on ease of catch-up and China's strategy.

Export controls on AI are US policy tools that restrict adversary (primarily Chinese) access to advanced semiconductors, AI models, capital, and related technology. They have been a centerpiece of US AI competition strategy since the Biden administration's October 2022 chip export controls.

Mechanisms

The control regime operates through several distinct instruments:

  • Chip export restrictions: limiting sale of advanced GPUs and semiconductor manufacturing equipment to China.
  • Investment restrictions: blocking US capital flows into Chinese AI and semiconductor firms.
  • Entity lists: designating specific Chinese firms and institutions as restricted.
  • Allied coordination: working with Japan, the Netherlands, South Korea, and others to prevent circumvention through third countries.

The Bureau of Industry and Security (Bureau of Industry and Security (BIS)), a Commerce sub-agency, writes and enforces the chip and equipment controls. The BIS Framework for AI Diffusion (January 2025, rescinded May 2025) was the concrete BIS implementation of the chip and model export-control philosophy; no federal framework currently governs model weights after its rescission.

Export controls form one lane of a multi-channel denial strategy that also reaches design IP, human capital, and model weights. Each channel uses different tools and faces different limiting factors:

ChannelToolLimiting factor
Hardware (chips, equipment)BIS export controls, Entity ListSmuggling, cloud-rental, third-country diversion
Design IP (architectures, specs)§1831 economic-espionage prosecution, trade-secret lawDetection inside US companies
Human capitalVisa / clearance policyTrade-off with US research capacity
Model weights[[bis-ai-diffusion-ruleAI Diffusion rule]] (rescinded May 2025)No current federal replacement

After the AI Diffusion rule's May 2025 rescission, three of the four denial channels remain active; the model-weights channel has no federal framework. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary); see AI and National Security for full treatment.)

Strategic rationale and positions

Jake Sullivan and Noah Feldman frame export controls as an implicit subsidy to the US AI industry: by constraining competitors, they raise the value of American firms and channel private capital toward them (Geopolitics in the Age of Artificial Intelligence, Foreign Affairs, 2026-01-27).

Dario Amodei takes a stronger position than Sullivan and Feldman, calling chip export controls "the most important single action we can take" to prevent AI-enabled authoritarianism. His argument holds that China is several years behind the US in frontier chip production; that the period for building "powerful AI" is very likely within those next several years; that selling chips to China is analogous to "selling nuclear weapons to North Korea and then bragging that the missile casings are made by Boeing"; and that because the CCP has the clearest path to using AI for totalitarian control, denying it compute is the most effective bottleneck. Amodei's framing presents export controls as nearly unconditionally important, going beyond Sullivan and Feldman's context-dependent analysis; the difference may reflect Amodei's higher confidence that powerful AI is imminent (1–2 years) and that the CCP would use it for authoritarian ends. (Source: The Adolescence of Technology)

Anthropic's institutional position is set out in "2028: Two Scenarios for Global AI Leadership" (May 13, 2026), which translates the case into three concrete asks: (1) close the loopholes that prop up PRC compute access — chip smuggling, offshore data-center access (US export law reaches the sale of chips, not remote access to them), and gaps in semiconductor-manufacturing-equipment controls including DUV tooling, servicing, and maintenance; (2) defend US innovations by restricting model access and deterring distillation attacks, including a legislative clarification that distillation is illegal; and (3) champion the export of trusted American AI. The paper cites an IFP estimate that, with strengthened restrictions, the US would have roughly 11 times more compute than China's AI sector, and a CFR estimate that Huawei produces ~4% of NVIDIA's aggregate compute in 2026 and ~2% in 2027. It frames the boundary condition explicitly: efficiency and algorithmic progress are a function of compute, not a substitute for it, so the compute lead is expected to compound into an algorithmic and capability lead. (Source: 2028: Two Scenarios for Global AI Leadership (Anthropic))

Context-dependent effectiveness

The value of export controls varies across the Eight Worlds Framework:

ScenarioEffectiveness
Catch-up is hardHigh — controls compound US advantage over time
Catch-up is easy (model-level)Moderate — controls slow but don't prevent replication
China builds alternative compute stackLow — chip controls become essentially useless
Diffusion race (Worlds 7, 8)Potentially counterproductive — may hinder US deployment abroad

Several recurring tensions follow from this conditional value. Controls that restrict chip sales may also restrict AI Diffusion of US systems to partners. Over-restriction risks accelerating China's push for semiconductor self-sufficiency. Enforcement faces circumvention through third countries and smuggling networks.

The CSIS analytic reading (Allen, March 2025)

Gregory Allen's CSIS report, written in the weeks after DeepSeek-R1, offers a policy reading of the hardware picture and serves as the policy complement to SemiAnalysis's hardware reporting: where SemiAnalysis supplies die counts, HBM stack inventories, and ramp targets, Allen supplies the policy-maker's interpretation — what BIS should do, where controls worked or failed, and how to forecast the lead.

Allen characterizes the controls as flawed rather than failed. The October 2022 package's A800 loophole let roughly $9B in advanced chips reach China legally during a roughly 12-month window, and enforcement is under-resourced: BIS operates with fewer than 600 employees and a roughly $200M budget overseeing trillions in activity. He nonetheless holds that the core premise — that constraining Chinese compute buys strategically meaningful time — remains sound conditional on enforcement.

Allen's top-line forecast is that the US lead is unlikely to exceed "more than a year or two, even with extremely aggressive export controls." On the binding constraint, he argues the gap is hardware rather than algorithms: open research, distillation, and informal knowledge transfer diffuse algorithms quickly, while compute infrastructure is where durable gaps live. He notes that the Jevons paradox applies — efficiency gains do not reduce total chip demand, and US firms announced roughly 50% capex increases post-DeepSeek.

DeepSeek's Liang Wenfeng publicly states that export controls are "the greatest challenge," with Chinese firms needing "two to four times" the compute of unrestricted access — primary-voice evidence that controls materially bind. Allen also confirms, via US government sources, that TSMC manufactured 2M+ Ascend 910B logic dies via Huawei shell companies, which he describes as a "strategically significant stockpile" and a direct export-control violation that extended Huawei's competitive runway.

Allen identifies the software ecosystem as the next chokepoint. CANN, Huawei's CUDA equivalent, remained immature — "difficult and unstable" per Huawei's own employees as of September 2024 — and DeepSeek's evaluation of it was "very negative." Google's TensorFlow-to-JAX migration (2–3 years) is a lower-bound proxy for CANN catch-up time; one risk is that a DeepSeek open-source community could accelerate CANN maturation.

The chokepoint-migration problem and HBM controls

Through 2025 the binding chokepoint on Chinese AI accelerators migrated from logic fabrication — where SMIC is catching up via 7nm-class DUV multi-patterning — to high-bandwidth memory (HBM). Policy tracked the migration. The December 2024 BIS rule restricted advanced HBM exports to China, acknowledging that HBM is the binding chokepoint. Before the rule, Samsung alone had directly supplied an estimated 11.4M HBM stacks to Chinese customers (Huawei and others). Post-rule, Huawei's 2026 ramp (a 600k 910C target) is gated on CXMT domestic HBM capacity of roughly 2M stacks in 2026 — enough for only 250,000–300,000 910C units. The pattern this illustrates is that export controls work only as long as they track the binding chokepoint: controls on logic without packaging, or packaging without memory, leak capacity to the weakest-link stage. (Source: Raw Sources/SemiAnalysis - CoWoS and HBM Supply Chain.md; Source: Raw Sources/SemiAnalysis - Huawei Ascend Production Ramp.md; see Semiconductor Supply Chain for the full chokepoint map.)

China's self-sufficiency drive

Ren Zhengfei is coordinating a roughly 2,000-company Chinese semiconductor consortium plus roughly 30 advanced-lithography organizations — described as "Spare Tire 2.0" — targeting 70% Chinese semiconductor self-sufficiency across the value chain by 2028, with reportedly effective "blank check" CCP backing. Analyst consensus (RUSI, CETaS, American Affairs) holds that this is attainable in mature nodes, packaging, and some DRAM, but unlikely at EUV, leading-edge logic, and HBM parity by 2028. This strengthens the long-timeline backfire argument below, in that the controls may be accelerating the very capability-build they are meant to prevent. (Source: Raw Sources/SemiAnalysis - Huawei Ascend Production Ramp.md)

The long-timeline backfire argument

Toby Ord (Broad Timelines, 2026) argues that in longer-timeline worlds, with transformative AI arriving in 2035 or later, export controls "may well have backfired, helping China get ahead on chips by incentivising them to build out their own chip industry and giving them 13 years to get good at it." Ord notes that this was a dynamic the White House considered while drafting the controls, but that the White House was focused on shorter timelines. He also notes that by 2035 China may have invaded Taiwan, depriving the West of its biggest source of chips.

Epoch AI's analysis (2026) provides quantitative context: compute is the dominant competitive factor, and Chinese labs probably cannot fully bridge a 10× gap through efficiency alone. But the compute gap had not grown sharply as of that analysis, and Chinese labs are finding ways to get more compute through smuggling and cloud rental. (Source: epochai.substack.com)

A paper circulating by July 5, 2026 offers empirical support for a software-side variant of the backfire argument: it finds that US chip export controls pushed China toward open-source AI as resilience infrastructure. After each major export-control event since 2022, LLM-repository forking jumped by 0.143 additional forks per repository-week among China-linked developers, versus 0.012 for US developers — an 11× gap — while Chinese open models such as Qwen and DeepSeek spread globally but are rarely disclosed in US patents (Source: arxiv.org). See Open-Source AI / Open-Weight Models.

The Sun feedback-loop critique (PEAT framework, May 2026)

Charles Sun's May 6, 2026 Lawfare essay, The Incentive Architecture Export Controls Cannot Reach, argues that US export controls strengthen rather than weaken the Chinese AI incentive architecture by deepening firm dependence on state-subsidized domestic compute (see PEAT — Proactive Elite Alignment Theory and The Incentive Architecture Export Controls Cannot Reach (Sun, Lawfare, May 6 2026)). The essay sets out a four-step feedback loop:

  1. Export controls restrict the supply of advanced foreign chips to Chinese firms (the intended effect).
  2. Restricted foreign chip supply increases dependence on state-subsidized domestic compute (Beijing Yizhuang: 40% reimbursement for domestic chips, 30% for non-domestic; Hangzhou: 30% / 20%).
  3. Deeper resource dependence strengthens the incentive for firms to align with state priorities, because the differential subsidy structure makes alignment the path of least resistance.
  4. Aligned firms use every available pathway to acquire capabilities, so distillation of American frontier models is a rational response rather than primarily espionage or defiance.

The loop closes because distillation triggers calls for tighter export controls, which further restrict foreign chip supply, deepening resource dependence and strengthening the alignment incentive.

Sun frames a boundary condition: the loop holds only as long as domestic computing is sufficient to produce competitive models. He cites Lennart Heim's RAND analysis that frontier training consumes only a fraction of total compute capacity, and concludes that the boundary condition has not been reached. (Source: rand.org)

Sun describes his argument as not a brief against export controls but a structural claim that the incentive system on the Chinese side is not addressable by supply-side US tools; demand-side tools would have to operate on the Chinese internal price structure, outside the reach of the Entity List, IEEPA, and ECRA. Sun's framework engages explicitly with Joe Khawam (Just Security, February 2026 — phased sanctions escalation) and Ryan Fedasiuk (War on the Rocks, April 2026 — regulatory tools to limit Chinese open-source diffusion), holding that both are correct about the tools available to the US but that neither engages the incentive system on the other side.

Industrial espionage and the Linwei Ding case

The Linwei Ding conviction (January 30, 2026) demonstrates the design-IP and human-capital lane of the denial strategy and illustrates why chip controls alone are insufficient. Ding, a former Google software engineer, was convicted on seven counts of economic espionage (§1831) and seven counts of trade-secrets theft (§1832). Between May 2022 and April 2023 he exfiltrated more than 2,000 pages on TPU chip architecture, GPU systems, SmartNIC, and cluster-communication software — effectively the full stack for a hyperscale AI training system — while simultaneously negotiating to become CTO of one PRC AI company (Rongshu Lianzhi Technology) and founding another (Shanghai Zhisuan Technology). It was the first US §1831 conviction on AI-related charges. (Already tracked via DOJ: Former Google Engineer Convicted of Economic Espionage (Linwei Ding).)

The case demonstrates that the PRC is actively pursuing the AI-compute design IP that chip export controls are meant to deny, making the two tools complements rather than substitutes. It also exposes a civil-military-fusion problem: CSET's September 2025 and February 2026 reports show roughly 75% of PLA AI procurement runs through nontraditional vendors — the same ecosystem Ding's PRC affiliates sit in — which weakens end-use certification for any dual-use export, because the nominal civilian customer is structurally entangled with PLA procurement chains. (See China's Military AI Wish List, CSET, February 2026, on PLA AI procurement demand-side and how military-civil fusion gives civilian chip controls military implications.)

Affirmative complement: EO 14320 (AI Exports Program)

Rather than relying solely on restriction, the Trump administration paired export controls with an affirmative promotion strategy. EO 14320 (July 23, 2025, "Promoting the Export of the American AI Technology Stack") creates the American AI Exports Program, under which industry-led consortia propose full-stack AI packages — hardware, data pipelines, models, cybersecurity, applications — for priority export to specific countries or regional blocs. Selected packages gain access to Export-Import Bank financing, DFC co-investment, and State Department diplomatic support.

The policy logic is that if chip controls deny Chinese AI access to third-country markets, the AI Exports Program pulls those markets toward US AI ecosystems with active financial incentives, extending the competition from chips to full AI stacks and to governance norms. EO 14320's diplomacy provisions direct the State Department to help partner countries build "pro-innovation regulatory environments conducive to the deployment of American AI systems," making US governance norms an export product alongside the technology. This parallels China's approach in its Belt and Road AI partnerships, where infrastructure financing brings Chinese AI standards along with it. (Sources: Executive Order 14320 — Promoting the Export of the American AI Technology Stack legislation page; Executive Order 14320 — Promoting the Export of the American AI Technology Stack source page; America's AI Action Plan, White House, 2025.)

Domestic weaponization risk

The Anthropic–Department of War conflict (Clawed, Ball, 2026) describes the Trump administration threatening to designate Anthropic a "supply chain risk" — a status normally reserved for foreign adversaries such as Huawei — for refusing to remove use restrictions on Claude in classified contexts. Ball argues that this makes American AI riskier to use for corporations and foreign governments, since the regulatory threat now applies to all American software; renders DeepSeek somewhat less risky relative to American AI from a regulatory perspective; effectively declares the American AI Exports Program "dead on arrival"; and treats private property rights and contractual freedom as subordinate to government demands. The result, on Ball's reading, is a paradox in which the same administration pursuing export controls to prevent adversary access to American AI is simultaneously weaponizing regulatory tools in ways that push allies toward non-American alternatives.

The June 2026 Commerce Department directive against Anthropic's Fable 5 and Mythos models illustrated the same dynamic applied to a model rather than a contract. According to TechCrunch reporting on June 19, 2026, the export-control directive forced Anthropic to cut access to Mythos — described as previously available to roughly 150 vetted companies and government bodies — within about 90 minutes of notification, after Anthropic reportedly granted Mythos access to a South Korean telecom (widely reported as SK Telecom, which denies ties to China) and Amazon CEO Andy Jassy flagged a Fable 5 safeguard bypass. The episode applied the licensing logic of export controls to the foreign-access conditions of a domestically developed model, the mechanism TechCrunch's account compared to earlier encryption and spyware export regimes that did not prevent diffusion (Source: techcrunch.com). Presidential AI adviser David Sacks said on June 22, 2026 that he had focused extensively on the security challenges tied to Mythos and that AI companies and the federal government must partner to address cyber vulnerabilities before adversaries exploit them (Source: insideaipolicy.com). On June 24, 2026 Anthropic published a statement characterizing the directive — which required it to suspend all access to Fable 5 and Mythos 5 — as resting on illegitimate cybersecurity concerns (Source: anthropic.com), and the Abundance Institute and Americans for Responsible Innovation united in opposition, a coalition crossing the usual pro- and anti-regulation divide and reflecting the industry framing of the action as an unprecedented de facto licensing regime (Source: insideaipolicy.com). Opposition extended into the administration's own orbit: on June 25, 2026 venture investor Marc Andreessen, a member of the President's Council of Advisors on Science and Technology, said he opposed the order requiring Anthropic to withdraw Fable access (Source: insideaipolicy.com). The directive drew the first court challenge to the use of export-control authority against a commercial AI model — rather than hardware — when Legion LegalTech Corp., a San Jose legal-technology company dependent on the models, sued the United States in the U.S. District Court for D.C. on June 23, 2026 (reported June 24), seeking to vacate the directive; Anthropic is not a party (Legion v. United States (Anthropic export-directive challenge)) (Source: msn.com). See Anthropic, Anthropic v. United States (Pentagon ban challenge).

On June 26, 2026 the Trump administration partially rescinded the directive, clearing more than 100 vetted companies and federal agencies — many of them participants in Anthropic's Project Glasswing — to regain access to Mythos 5, Anthropic's strongest cybersecurity model, while Fable 5 remained blocked. In a letter to Anthropic chief compute officer Tom Brown, Commerce Secretary Howard Lutnick wrote that the company had made "significant progress" addressing the government's risk concerns and that Mythos 5 would no longer require an export license for trusted firms and their non-citizen employees (Source: politico.com; scmp.com). Anthropic welcomed the move and said it was working to restore access "as quickly as possible"; the Foundation for Individual Rights and Expression (FIRE) and OpenAI's Sam Altman criticized the government's case-by-case selection of who may use the most capable models (Source: scmp.com). The Verge reported that Anthropic had kept its Mythos-class models offline for two weeks following the June 12 order, that cofounder Tom Brown replaced CEO Dario Amodei in Washington negotiations alongside policy chief Sarah Heck, and that there was no clear framework for applying export controls to AI systems; the trigger was reportedly a method for bypassing Fable 5's guardrails to surface security vulnerabilities, flagged to officials by Amazon CEO Andy Jassy, while security researcher Katie Moussouris, who reviewed the report at Anthropic's request, called the concern overblown and an essential defensive coding capability (Source: theverge.com). On June 27, 2026 the administration moved toward also restoring access to Fable 5, the second model still blocked, according to a source cited by Axios (Source: reuters.com).

The episode closed on June 30, 2026, when the Commerce Department withdrew the export controls on both models, ending the suspension that began June 12; Lutnick wrote in a June 30 letter that Anthropic "has agreed to proactively detect and address security" issues (Sources: anthropic.com; insideaipolicy.com; decrypt.co). Anthropic redeployed Fable 5 globally on July 1, 2026 with a new safety classifier it says blocks the reported bypass in over 99% of cases (rerouting blocked requests to Opus 4.8), restored Mythos 5 to US organizations under the June 26 approval, and said it is drafting a jailbreak-severity framework with Amazon, Microsoft, Google, and other Glasswing partners while calling for "strong regulation"; Inside AI Policy reported industry stakeholders pressing for policy clarity on how export-control authority applies to AI models going forward (Sources: anthropic.com; insideaipolicy.com).

A CSIS Critical Questions analysis published June 16, 2026 (The Department of Commerce Restricted Access to Anthropic's Latest Models. What Comes Next? (CSIS, June 2026)) sets out the statutory objections that made the action contested on its own terms rather than only on policy grounds. The letter reportedly relied on ECRA's emerging-and-foundational-technology authority, for which "there is no regulatory framework in the EAR… which is why it has never been used before as the basis for issuing a control." It also reportedly cited 15 C.F.R. § 744.22, which "only allows Commerce to impose license requirements on a small group of adversarial countries, not a worldwide control." And it cited § 734.13 to bring model access within EAR scope, though "this exact section was used by Commerce in three previous Advisory Opinions as the reason why remote access transactions are not subject to the EAR." CSIS points to the House's passage of the Remote Access Security Act as legislative evidence on the same point, passed "precisely" because "ECRA does not authorize regulating remote access." Separately, the January 2025 AI diffusion rule does control model weights, but "is not currently being enforced pursuant to a May 2025 announcement by BIS."

CSIS's assessment of the spillover was that although the control reached only Anthropic, "the confusion over BIS's authority to impose it raises uncertainty for all of U.S. industry," and that the vulnerability driving the action "is not restricted to Fable and is inherent to all modern language models" — from which it drew the standards objection that the episode "risks creating an impossible bar—that the U.S. government will only allow the public release of models that cannot be jailbroken, even in theory." Its positive recommendation separates instrument from target: export controls "have a role to play in controlling access to certain physical components in the AI supply chain, most notably the computing capacity needed to train and operate advanced models," but "are not a clear fit for resolving national security concerns for how models are being accessed and used" (The Department of Commerce Restricted Access to Anthropic's Latest Models. What Comes Next? (CSIS, June 2026)).

China response to the Mythos restrictions

The US restrictions on Anthropic's Mythos-class models surfaced Chinese and other non-US alternatives positioned around cybersecurity capability and the absence of export controls. Security researchers said Z.ai's open-weight GLM-5.2, released in June 2026, can match the latest US models at finding software security bugs, though it still trails Anthropic's and OpenAI's systems on other tasks; businesses were reported to be exploiting the narrowing gap to cut costs, with companies including Microsoft weighing how to offer Chinese models (Source: wsj.com). On June 24, 2026 Chinese cybersecurity firm 360 (Qihoo 360) unveiled Tulongfeng, a vulnerability-discovery tool it said rivals Anthropic's Mythos, alongside Yitianzhen for automated cyber defense; founder Zhou Hongyi described vulnerability-finding AI as a national strategic asset and warned of "one-way transparency." Tokyo-based Sakana AI launched Fugu, a frontier model it said stands "shoulder-to-shoulder" with Anthropic's Fable 5 and Mythos Preview, built to orchestrate other models and marketed as "frontier capability without the risk of export controls." Both launches followed the US mid-June 2026 order (Source: techcrunch.com). See Qihoo 360, Zhipu AI, Sakana AI, GLM-5 and GLM-5.1.

China also moved toward export controls of its own. Reporting made public July 6, 2026 said the Ministry of Commerce had held meetings with top Chinese technology firms over the preceding month about restricting overseas access to the country's most advanced AI models — both closed and open-source — treating frontier AI as a strategic national asset (Source: finance.yahoo.com). Reuters identified the firms as Alibaba, ByteDance, and Z.ai, said the proposed curbs extend to unreleased models, and reported that the Ministry of Commerce–led discussions also covered criminalizing theft or leaks of proprietary AI technology and new rules on funding domestic AI startups (Source: reuters.com). Such curbs would mirror, from the Chinese side, the deployment-gating posture the US applied to Mythos-class models in June 2026. See Chinese AI Policy. Subsequent Reuters reporting on July 8, 2026 described Chinese authorities as weighing a "silicon curtain" of restrictions around sought-after domestic AI models (Source: reuters.com).

The model-security front of the standoff also escalated in the other direction: on July 8, 2026, a cybersecurity threat platform operated by China's Ministry of Industry and Information Technology issued a "backdoor" security alert over Anthropic's Claude Code, saying it had found security vulnerabilities in the coding tool — following the Claude Code tracker disclosures and Alibaba's employee ban (Source: reuters.com). See Anthropic.

Movement also appeared on the hardware side of the standoff. Per reporting published July 8, 2026, China planned to allow some of its biggest AI companies to buy limited quantities of Nvidia H200 chips to offset a domestic shortage caused by soaring demand; the U.S. had cleared roughly ten Chinese firms for H200 purchases in May 2026, but no deliveries had occurred amid Beijing's guidance against foreign chips (Source: theinformation.com). The US-side licensing subsequently widened: documents made public July 14, 2026 show the U.S. licensed ZTE Kangxun Telecom and server maker Maginfra to purchase Nvidia H200 chips, and cleared Kingsoft subsidiary Zhuhai Hengqin Yunxiang Zhisheng to buy rival AMD chips — expanding beyond the roughly ten firms, including Alibaba, Tencent, ByteDance, and JD.com, cleared in May 2026 (Source: reuters.com).

A Special Competitive Studies Project brief published July 10, 2026 read the two-way pattern together: Beijing moving to control the chips and AI models it depends on — including restricting its own companies' frontier models — while DeepSeek designs its own chip and the door to Nvidia chip sales in China opens slightly (Source: scsp222.substack.com).

Enforcement and recent measures

Several 2026 actions extended or illustrated the control regime. Nvidia's H200 was fully blocked from China exports under an expanded BIS rule, confirmed April 22, 2026. (Source: reuters.com)

Enforcement also extended to allied jurisdictions. On April 22, 2026 a Samsung researcher was sentenced to 7 years for leaking DRAM and HBM IP to CXMT in China — a prosecution data point on the Korean side of supply-chain protection. (Source: english.hani.co.kr)

Two State-level diplomatic and policy measures followed. The OSTP NSTM-4 memo (April 23, 2026) opened an export-control-adjacent lever framed around adversarial distillation (see Adversarial Distillation). A State Department global cable (April 24, 2026) directed posts to spotlight alleged DeepSeek IP theft. (Source: reuters.com)

Enforcement attention also reached the lithography supply chain. On June 19, 2026, Commerce Secretary Howard Lutnick questioned ASML's leadership over concerns, reported by Bloomberg, that China may have obtained one of the company's extreme-ultraviolet (EUV) lithography machines in violation of export restrictions; ASML denied that any such system had reached China (Source: reuters.com). The dispute remained unresolved into July: a July 5 report described the United States as alleging China may have obtained an advanced EUV machine while ASML fought to rebut the claims (Source: economist.com). By July 18, 2026, ASML's rebuttal was reported in specific terms: the company says it knows the exact location of all 340 EUV machines it has produced, including 26 decommissioned units, none of which is in China (Source: ground.news). EUV tools remain the principal chokepoint that China is not expected to reach parity on by 2028.

Criminal enforcement of chip-diversion controls advanced in Singapore, where prosecutors on July 6, 2026 filed additional charges, including money laundering, against a key suspect in the Nvidia AI-server fraud case, expanding a probe tied to US chip export controls (Source: bloomberg.com).

Reporting made public on July 10, 2026 identified a gap on the model side of the regime: OpenAI and Google supplied advanced AI model access to Singapore-based subsidiaries of Alibaba, Baidu, and Tencent — Chinese technology groups on the Pentagon's military-ties blacklist — lawfully, because the U.S. export-control regime covers physical chips crossing borders but not hosted model access (Source: ft.com; techieray.substack.com). See Alibaba / Qwen Team, Tencent / Hunyuan.

Two July 2026 measures adjusted the regime in opposite directions. Nvidia more than halved its list of Asian customers authorized to buy advanced AI chips, per July 13 reporting, introducing a "white list" with tougher vetting in Singapore, Malaysia, and Japan to close China-diversion loopholes (Source: ft.com). Meanwhile, the U.S. loosened export controls on the UAE on July 10, 2026, easing Nvidia AI-chip sales; the Gulf state's flagship AI firm G42 can now freely buy chips — described in July 14 reporting as a reward for UAE support of the U.S. war in Iran — and plans to become a U.S. company (Source: wsj.com; investing.com). The UAE track had an intelligence-community foundation: per a July 19, 2026 account, the CIA vetted G42 through an operative posted to Abu Dhabi in 2023 under diplomatic cover, clearing the way for expanded chip access and the planned 1-gigawatt Stargate UAE cluster (Source: wsj.com).

Congressional attention extended to intellectual-property channels beyond chips: in a letter to Commerce Secretary Howard Lutnick made public July 9, 2026, Sen. Jim Banks (R-IN) urged the U.S. Patent and Trademark Office to counter Chinese companies' use of AI tools "to scrape U.S. patent applications and accelerate the theft of American intellectual property," highlighting biotechnology (Source: insideaipolicy.com).

Congressional pressure also moved toward import-side restrictions on Chinese memory. On July 16, 2026, the chair of the House China committee urged the Trump administration to ban U.S. companies from buying memory chips from Chinese makers CXMT and YMTC, warning that Apple's lobbying for access to Chinese memory poses what he characterized as a grave national-security risk (Source: ft.com). A purchase ban would extend the regime from controlling what leaves the U.S. to restricting what American companies may buy — the demand-side complement to the HBM export restrictions described above. The pressure coincided with CXMT's own capital raise: on July 15, 2026 the Chinese DRAM maker filed for an $8.6 billion Shanghai IPO at a roughly $86 billion valuation, as two U.S. lawmakers urged Commerce to blacklist the company (Source: theinformation.com).

On the licensing side, BIS Under Secretary Jeffrey Kessler testified to Congress — as became public July 17, 2026 — that a "trivial" number of Nvidia H200s had shipped to China under licenses, drawing criticism from Rep. Bill Huizenga (Source: transformernews.ai).

The hosted-model gap identified in July resurfaced in August in a form that also raised conflict-of-interest questions. Reuters reported on August 17, 2026 that World Liberty Financial is collaborating with WorldClaw, a Hong Kong-based venture that offers AI models and accepts World Liberty's USD1 stablecoin as payment. A Reuters review found that 43 of the 90 models on WorldClaw's website came from Alibaba, Baidu, Z.ai and other Chinese companies the administration has flagged, including firms the Defense Department designates as Chinese military-aligned and Z.ai, which sits on the Commerce Department entity list. The Trump family owns 38% of World Liberty; White House spokesperson Anna Kelly said there are no conflicts of interest (Source: reuters.com). The arrangement turns on the same distinction as the July finding: entity-list designation restricts transactions in goods and technology, and model access served from outside the United States is not covered in the way physical chips crossing borders are.

Relationships

Sources