AI Policy Wiki
Dashboard

Location Verification for AI Chips (IAPS, issue brief May 2025)

medium confidence · updated 2026-07-26

IAPS proposal for verifying AI-chip location using existing hardware: chips attest their identity to a trusted landmark server, and round-trip delay bounds the maximum distance by the speed of light. Estimates a firmware update under $1 million and a network of 100–500 landmarks at roughly $25,000 each per year, and argues Nvidia could recoup the cost through the sale of 500 additional controlled chips. Distinguishes verification from geofencing and addresses privacy, backdoor, and competition objections.

Issue brief written May 2025 by Asher Brass for the Institute for AI Policy and Strategy, based on a fuller 2024 report by Asher Brass and Onni Aarne.

The enforcement gap

The brief's premise is that export controls are undermined less by legal gaps than by the absence of visibility: chips "are being sold to apparent start-up companies in countries such as Malaysia and Singapore, which promptly disappear after smuggling the chips into China," with a forthcoming CNAS working paper estimating "the number of chips smuggled in 2024 to be in the hundreds of thousands."

The finding that motivates a technical fix is about the regulator rather than the smuggler: "even the Bureau of Industry and Security does not know exactly how much of this kind of smuggling is happening, or in which countries, because they do not have sufficient resources to inspect even a minority of these companies."

The mechanism

The proposal uses a capability the brief says modern chips already have: they "can securely verify their own identity through a process called attestation, based on a unique cryptographic key held on each chip." Location follows from physics rather than from any positioning system — "by establishing a trusted landmark server at a known location, and asking an AI chip to verify its identity to that landmark server, we can measure the delay of the response and determine a maximum plausible distance between the landmark and the chip in question, based simply on the speed of light."

The worked example: a 1-millisecond response, at 186 miles per millisecond, bounds the round trip at 186 miles and so the distance at 93 miles. "If the landmark is in Taiwan for example, this would be sufficient to prove that the chip cannot be in mainland China."

A prototype exists: "A rudimentary version of location verification of Nvidia H100 chips has already been successfully prototyped," with a Singapore landmark verifying a chip within 300 miles.

Cost

Two steps, which the brief estimates "could likely be completed within six months":

StepEstimated cost
Firmware and software update enabling rapid location verificationunder $1 million
A network of 100–500 trusted landmark servers near major data centers~$25,000 per landmark per year, i.e. $2.5–12.5 million annually

The argument for vendor adoption is commercial rather than regulatory: "In Nvidia's case, the costs of a location verification system could likely be recouped if it enabled the sale of just 500 additional controlled AI chips. Nvidia exported hundreds of thousands of such chips in 2024." That is, verification pays for itself if it permits even a marginal loosening of controls.

Objections addressed

The brief answers seven objections directly, and the distinctions it draws are what make the proposal legible as a governance mechanism rather than a control mechanism.

  • Why not GPS. "GPS signals are easily spoofed and AI chips lack built-in receivers; delay based verification instead leverages each chip's cryptographic key, making spoofing far harder."
  • Privacy. Verification "would target chips in data centers and shares no personal data, so it avoids conflicts with privacy regulations such as GDPR."
  • Backdoor. "Verification is initiated and controlled by the chip's owner: the chip signs a simple ping with its hardware root of trust, and no user data ever even needs to leave the local data center network."
  • Versus geofencing. The central distinction: "Verification simply verifies approximate location; geofencing would forcibly disable a chip outside a zone and is far more difficult to implement, and potentially open to abuse."
  • Competition. Implementation is "lightweight (e.g., by integrating the Caliptra open source root of trust), and small vendors selling to low-risk customers could be exempt."
  • Landmark operation. "Either the chip maker or a neutral U.S. entity can run them under BIS-defined standards, with regular audits and spot physical inspections."
  • Chips in transit. Chips in transit or storage cannot verify, so the requirement would attach on installation, with prolonged unverified periods treated as a flag for investigation.

The brief's policy argument runs in the direction of loosening rather than tightening: better visibility would give BIS "near real time visibility into where smuggling is likely to be happening," which would allow enforcement to be targeted and "reduc[e] the need for blunt export controls covering many countries." It repeats the point in the competition answer: verification "could also allow more permissive export control rules by making enforcement easier after the fact."

Relationships