Since 2022, the U.S. government has restricted exports of the most advanced AI chips to China and other countries of concern. But smugglers have repeatedly circumvented those controls, diverting hundreds of thousands of chips. One estimate suggests that—in 2024 and 2025 alone—over 450,000 advanced AI chips were smuggled into China; that’s one to two cutting-edge AI supercomputers’ worth of compute as of early 2026. The United States government has ramped up enforcement to address this issue, but chips are still slipping through the cracks and into smugglers’ hands.
Increasingly, U.S. policymakers see location verification methods, which help regulators determine where AI chips are physically located, as good options to detect potential smuggling and improve export control enforcement. But how viable and costly are these approaches, and how much do they actually help national security?
CSET’s Jacob Feldgoise, Kyle Miller, and Hanna Dohmen dove deep into investigating how location verification methods can—and cannot—improve enforcement of export controls on these powerful chips, culminating in their report, Tracking AI Chips: Assessing Location Verification as an Export Control Enforcement Tool. I sat down with Jacob to learn more about the issue, their findings, and what those findings mean for mitigating AI chip smuggling.
AI chips are undoubtedly being smuggled into China. How is that happening and at what scale?
Two aspects of the AI chip trade make smuggling easier. First, it’s a globalized value chain. While most AI chips sold abroad are designed by U.S. companies, they aren’t manufactured in the U.S., which makes it much more difficult for U.S. law enforcement to detect when they’re diverted or to intervene. Second, AI chip designers often don’t sell directly to end users. Instead, the AI chip might pass through a server manufacturer, a distributor, and a reseller on its way to the end user. So, each transaction creates an opportunity for smuggling.
Part of the problem is that we don’t know exactly how many AI chips are being smuggled into China, but we do have a few clues. Indictments by the U.S. Department of Justice (DOJ) and investigative journalism have revealed over ten AI chip smuggling schemes, which collectively set a minimum for the total volume of smuggling. Building on those reports, researchers at Epoch AI and CNAS have created statistical models of total smuggling volume. There’s a lot of uncertainty in these estimates—mainly because we only know about the diversion that’s been detected. Chip smuggling is like an iceberg: we see only what’s above the surface. To estimate its true scale, we need to know how much is hidden below the waterline—and whether that’s 50% or 90% makes a big difference.
What are the traditional ways of enforcing export controls, and why are these methods struggling to catch AI chips being diverted?
The U.S. Department of Commerce’s Bureau of Industry and Security—also known as BIS—is responsible for administering and enforcing U.S. export controls. To identify potential diversion, BIS draws on trade and licensing data, all-source intelligence, industry tips, voluntary self-disclosures, and findings from overseas end-use checks. These methods do detect smuggling, as shown by the various DOJ indictments we’ve seen so far. But we shouldn’t expect enforcement efforts to completely prevent smuggling. That would be impossible. Instead, the goal is broadly to detect and disrupt large smuggling rings to reduce future diversion.
That being said, the existing system is struggling to sufficiently enforce export controls on AI chips. This has led researchers and members of Congress alike to look for ways to improve enforcement—which the proposed Chip Security Act aims to do by requiring location verification of AI chips.
Chip smuggling is like an iceberg: we see only what’s above the surface. To estimate its true scale, we need to know how much is hidden below the waterline—and whether that’s 50% or 90% makes a big difference.
Your report looks at a few broad categories of enforcement approaches that could help verify where AI chips are located once they’re exported. How can these location verification methods mitigate AI chip smuggling? What did your research uncover about these methods?
In general, location verification methods can help export control enforcement by generating leads and raising the costs of smuggling. Location verification would generate enforcement leads by flagging chips outside their intended locations. This would help BIS investigate diversion and develop more targeted rules. Location verification would also make smuggling more costly by forcing smugglers to spend resources circumventing or undermining it. These added costs could deter some smuggling, but exactly how much is unknowable.
We reviewed five categories of methods to help identify the location of a chip: physical inspections, mail-in inspections, video inspections, inventory management tools, and geolocation mechanisms. There are three main types of geolocation mechanisms: GPS-based methods use satellites to locate chips. Topology-based methods estimate where a chip is based on the networks it connects to. Ping-based location verification—also known as PLV—estimates a chip’s location by measuring the time it takes for signals to travel from a chip to trusted servers and back.
To evaluate these options, we developed a framework with four criteria: an effective location verification method must be verifiable, accurate, secure, and repeatable. We recommend that BIS initially allow companies to use any method that meets all four criteria. In our assessment, however, only physical inspections and PLV currently qualify. The other methods fall short on security, and some also fall short on verifiability or accuracy.
To determine whether physical inspections or PLV is more cost-effective, we simulated more than 10 million scenarios and then modeled cost and the number of diverted chips each method would be expected to detect in each scenario. We found that PLV is the more cost-effective approach because physical inspections didn’t detect more diverted chips per dollar than PLV in any of the scenarios we simulated. Still, PLV does have serious limitations that reduce its usefulness.
While we think PLV is the most viable and cost-effective location verification approach of the ones we reviewed, physical inspections should be seen as a useful supplement to PLV, especially for follow-on enforcement.
You mentioned some of the benefits the U.S. government would gain from ping-based location verification. What can’t PLV achieve—even if implemented properly?
We identified five key limitations of PLV, most of which apply broadly to the other location verification methods.
The first limitation is that chips already in circulation could support PLV only if end users install a software or firmware update, which requires compliance. And hardware-based PLV can’t be added to chips after they’re already manufactured.
Second: When a chip stops responding, PLV can’t tell whether it has been diverted, is in storage or transit, or was deliberately disconnected to avoid detection.
Third: Well-resourced smugglers could fool PLV into reporting that a chip is still where it should be. Even strong security measures cannot fully eliminate this risk.
Fourth: Even under ideal conditions, PLV would likely be accurate to about 20 miles at best. It can’t reliably distinguish between nearby data centers run by different entities or determine which country a chip is in when it is close to an international border.
Fifth: PLV checks where chips are located—not who uses them. It can’t detect a transfer to an unauthorized user if the chip stays in the same location.
Taken together, these limitations make location verification much less useful than it might first appear.
If your recommendations were perfectly implemented, what would that mean for the U.S.-China AI competition? What would that mean for national security?
If policymakers do choose to implement location verification, our recommendations would help make it as cost-effective as possible. But given the limitations, we’re not convinced it is worth the cost. Whether or not location verification is adopted, policymakers should look to strengthen export control enforcement, including by bolstering BIS’s traditional enforcement methods and modernizing the Bureau’s IT operations.