{
  "schema_version": "1.4.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "G-0006",
    "slug": "enforce-chip-export-controls",
    "title": "Enforce chip export controls",
    "aliases": [
      "chip smuggling",
      "export verification",
      "end-location verification"
    ],
    "status": "draft",
    "last_reviewed": "2026-10-03",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": [
        "claude-review"
      ]
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Keep export-controlled AI chips at the destinations they were authorised for.",
    "summary": "The goal is to keep export-controlled AI chips at the destinations they were authorised for. Avellar and Grunewald write that a core challenge in enforcing export controls on advanced AI chips is verifying that the chips remain in their authorised destinations after export [[S-1402]]. Reuel and colleagues describe high-end data-centre AI chips as subject to US export controls and, at the time of writing, straightforward to smuggle [[S-0001]]. Verifying the goal means showing where exported chips are.",
    "claims": [
      {
        "id": "C-0002",
        "title": "Chips are where they are declared to be",
        "url": "https://trustbutveri.fyi/claims/chips-are-where-declared/",
        "assessment": true,
        "relevance": "direct",
        "note": "End-location verification asks whether controlled chips remain in their authorised locations or jurisdictions. Reuel and colleagues call it a key technical problem for enforcement that a chip's location cannot currently be known after export.",
        "sources": [
          "S-1402",
          "S-0001"
        ],
        "editorial": false
      }
    ],
    "outside": [
      {
        "label": "end-user and end-use verification",
        "text": "Avellar and Grunewald also cover end-user verification, such as know-your-customer checks, and end-use verification, such as audits of compute provisioning. This map has no records for these compliance processes.",
        "sources": [
          "S-1402"
        ],
        "editorial": false
      }
    ],
    "sources": [
      {
        "source": "S-1402",
        "supports": "core enforcement challenge; end-location, end-user and end-use verification; methods; on-site inspections matching chip counts and serial numbers; relevance to future international agreements",
        "locator": "abstract; executive summary; §1"
      },
      {
        "source": "S-0001",
        "supports": "export-controlled chips straightforward to smuggle; location or owner not currently knowable after export; verifiable latencies to trusted servers",
        "locator": "§5.2.1"
      },
      {
        "source": "S-3382",
        "supports": "recommendations for software-based location verification and a notification requirement for exports, re-exports and ownership transfers",
        "locator": "recommendations 2 and 3"
      }
    ],
    "order": 6,
    "type": "goal",
    "url": "https://trustbutveri.fyi/goals/enforce-chip-export-controls/",
    "source_file": "content/goals/enforce-chip-export-controls.md",
    "flags_all": [],
    "body_markdown": "## Proposals\n\n- **Avellar and Grunewald** examine verification mechanisms that could be put in place in about a year [[S-1402]]. They group them into end-location, end-user and end-use verification [[S-1402]]. End-location methods include export documentation checks, on-site inspections, random return requests and delay-based location verification [[S-1402]]. In the on-site inspections they describe, inspectors check that the number of chips at a facility, and their serial numbers, match what was reported [[S-1402]]. The authors add that these mechanisms could also help monitor future international agreements on AI [[S-1402]].\n- **Grunewald and Fist** recommend that AI chip designers implement software-based location verification [[S-3382]]. They also suggest a notification requirement for exports, re-exports and ownership transfers of controlled AI chips [[S-3382]].\n- **Reuel and colleagues** note that the location or owner of a chip cannot currently be known after it has been exported [[S-0001]]. One approach they describe is to measure verifiable latencies between the chip and a network of trusted servers [[S-0001]].",
    "body_text": "Proposals - Avellar and Grunewald examine verification mechanisms that could be put in place in about a year [S-1402]. They group them into end-location, end-user and end-use verification [S-1402]. End-location methods include export documentation checks, on-site inspections, random return requests and delay-based location verification [S-1402]. In the on-site inspections they describe, inspectors check that the number of chips at a facility, and their serial numbers, match what was reported [S-1402]. The authors add that these mechanisms could also help monitor future international agreements on AI [S-1402]. - Grunewald and Fist recommend that AI chip designers implement software-based location verification [S-3382]. They also suggest a notification requirement for exports, re-exports and ownership transfers of controlled AI chips [S-3382]. - Reuel and colleagues note that the location or owner of a chip cannot currently be known after it has been exported [S-0001]. One approach they describe is to measure verifiable latencies between the chip and a network of trusted servers [S-0001].",
    "referenced_by": []
  }
}