Issue brief written May 2025 by Asher Brass for the Institute for AI Policy and Strategy, based on a fuller 2024 report by Asher Brass and Onni Aarne.
The enforcement gap
The brief's premise is that export controls are undermined less by legal gaps than by the absence of visibility: chips "are being sold to apparent start-up companies in countries such as Malaysia and Singapore, which promptly disappear after smuggling the chips into China," with a forthcoming CNAS working paper estimating "the number of chips smuggled in 2024 to be in the hundreds of thousands."
The finding that motivates a technical fix is about the regulator rather than the smuggler: "even the Bureau of Industry and Security does not know exactly how much of this kind of smuggling is happening, or in which countries, because they do not have sufficient resources to inspect even a minority of these companies."
The mechanism
The proposal uses a capability the brief says modern chips already have: they "can securely verify their own identity through a process called attestation, based on a unique cryptographic key held on each chip." Location follows from physics rather than from any positioning system — "by establishing a trusted landmark server at a known location, and asking an AI chip to verify its identity to that landmark server, we can measure the delay of the response and determine a maximum plausible distance between the landmark and the chip in question, based simply on the speed of light."
The worked example: a 1-millisecond response, at 186 miles per millisecond, bounds the round trip at 186 miles and so the distance at 93 miles. "If the landmark is in Taiwan for example, this would be sufficient to prove that the chip cannot be in mainland China."
A prototype exists: "A rudimentary version of location verification of Nvidia H100 chips has already been successfully prototyped," with a Singapore landmark verifying a chip within 300 miles.
Cost
Two steps, which the brief estimates "could likely be completed within six months":
| Step | Estimated cost |
|---|---|
| Firmware and software update enabling rapid location verification | under $1 million |
| A network of 100–500 trusted landmark servers near major data centers | ~$25,000 per landmark per year, i.e. $2.5–12.5 million annually |
The argument for vendor adoption is commercial rather than regulatory: "In Nvidia's case, the costs of a location verification system could likely be recouped if it enabled the sale of just 500 additional controlled AI chips. Nvidia exported hundreds of thousands of such chips in 2024." That is, verification pays for itself if it permits even a marginal loosening of controls.
Objections addressed
The brief answers seven objections directly, and the distinctions it draws are what make the proposal legible as a governance mechanism rather than a control mechanism.
- Why not GPS. "GPS signals are easily spoofed and AI chips lack built-in receivers; delay based verification instead leverages each chip's cryptographic key, making spoofing far harder."
- Privacy. Verification "would target chips in data centers and shares no personal data, so it avoids conflicts with privacy regulations such as GDPR."
- Backdoor. "Verification is initiated and controlled by the chip's owner: the chip signs a simple ping with its hardware root of trust, and no user data ever even needs to leave the local data center network."
- Versus geofencing. The central distinction: "Verification simply verifies approximate location; geofencing would forcibly disable a chip outside a zone and is far more difficult to implement, and potentially open to abuse."
- Competition. Implementation is "lightweight (e.g., by integrating the Caliptra open source root of trust), and small vendors selling to low-risk customers could be exempt."
- Landmark operation. "Either the chip maker or a neutral U.S. entity can run them under BIS-defined standards, with regular audits and spot physical inspections."
- Chips in transit. Chips in transit or storage cannot verify, so the requirement would attach on installation, with prolonged unverified periods treated as a flag for investigation.
The brief's policy argument runs in the direction of loosening rather than tightening: better visibility would give BIS "near real time visibility into where smuggling is likely to be happening," which would allow enforcement to be targeted and "reduc[e] the need for blunt export controls covering many countries." It repeats the point in the competition answer: verification "could also allow more permissive export control rules by making enforcement easier after the fact."
Relationships
- supports: Compute Governance — a hardware-enabled mechanism using existing chip attestation
- related: Export Controls (AI) — argues verification permits looser rather than tighter controls
- related: Chip Smuggling and Export-Control Evasion, Nvidia, Bureau of Industry and Security (BIS), Institute for AI Policy and Strategy (IAPS)