Location verification methods have emerged as a key proposal to strengthen enforcement of export controls on AI chips. In an accompanying report, we assess the viability of various methods and find that two approaches—ping-based location verification (PLV) and physical inspections—are best suited to the task. This piece compares these two methods by modeling their cost and benefit across more than ten million simulated scenarios. We find that PLV is the more cost effective approach, as physical inspections did not detect more diverted chips per dollar than PLV in any of the scenarios we simulated.
Key Takeaways
Recent Congressional legislation proposes location verification—which would allow regulators to determine where AI chips are located—as a key way to strengthen export control enforcement. There are five categories of methods for location verification: physical inspections, mail-in inspections, video inspections, inventory management, and geolocation.1
Physical inspections involve recurring on-site audits by law enforcement personnel or contracted investigators to verify the chip locations. Mail-in inspections require end users to ship randomly selected chips to law enforcement personnel or contracted investigators for inspection. Video inspections involve such personnel or investigators remotely inspecting chips using tamper-resistant cameras shipped to the data center. Inventory management tools output a list of chips’ unique identifiers (e.g., serial numbers) present at a data center. Geolocation mechanisms use data automatically generated by chips, servers, and data center infrastructure to periodically identify and verify their locations. Ping-based location verification (“PLV”), a type of geolocation mechanism, measures the time it takes for a signal to travel from a chip to multiple trusted “landmark” servers and back.
In an accompanying report, we assess these methods’ viability for enhancing export control enforcement efforts using four criteria: verifiability, accuracy, security, and repeatability. We find that of all the available options for location verification assessed in the accompanying report, PLV and physical inspections satisfy each criteria and are therefore the best methods.
To determine which approach is better, we modeled their benefits and costs for over ten million simulated scenarios. We hypothesized that PLV would be more cost effective than physical inspections, which is why we deliberately chose model parameters favorable to physical inspections to determine whether PLV is more cost-effective even under those conditions. Moreover, we modeled two separate implementations for a PLV system: one model estimated costs based on a PLV system in which landmark servers are owned and operated directly by the Bureau of Industry and Security (BIS), chip designers, or a third party, while the second model estimated costs based on a PLV system in which landmark servers are rented from cloud service providers.
We compared the two methods using detections-per-cost: the expected number of diverted chips a method detects divided by the dollar cost (i.e., the higher the detections-per-cost, the more detections of diverted chips per dollar). We found that PLV is more cost effective than physical inspections. Physical inspections did not have more detections-per-cost than renting or owning PLV in any of the 10.5 million scenarios we simulated. In the vast majority of modeled scenarios, both PLV options had strictly higher detections-per-cost; in the remaining scenarios, physical inspections tied one or both PLV options but never outperformed either. We conducted sensitivity checks on all key constants and concluded that the model outcome is not sensitive to any of our choices.
Model Design
The model has three high-level steps, as outlined below. A detailed walkthrough of the model is available in Appendix A. We built the model in Python and published the code on GitHub.
- Select parameters for the variables in the model (described in the following list), resulting in millions of possible combinations. Each unique combination represents a different scenario. Any given scenario can have up to five scenario components, in which each component is the number of clusters of a unique size (e.g., four clusters with 100,000 chips each could be one scenario component).
- Estimate the expected detections and cost of PLV and physical inspections in each scenario and identify which method has a higher detections-per-cost.2
- Count the number of scenarios for which PLV wins, physical inspections win, or they tie (overlapping ranges of detections-per-cost).
We built a different scenario for each unique combination of the following parameters:
- Viable number of chips per cluster (i.e., cluster sizes): {10, 100, 1,000, 10,000, 100,000}
- Viable number of diverted chips per cluster: {0, 10, 100, 1,000, 10,000, 100,000}3
- Viable share of clusters that experience diversion per scenario component: {20%, 50%}4
- Viable number of chips tested in a cluster: {0, 10, 100, 1,000}5
Across all scenarios, we assumed a series of constants, which are listed below. Justifications and sensitivity checks for each chosen value are presented in Appendix B:
- Total number of tracked chips: 3 million chips
- Minimum number of clusters per cluster size: see Table B1
- Minimum number of chips diverted per cluster: 100 chips
- Minimum number of chips diverted per scenario: 114,000 chips
- Number of physical inspections per cluster per year: 2x
- PLV value discount multiplier: 0.5x
- Probability that a diverted chip is not detected by a physical inspection: 5%
- Probability that a diverted chip is not detected by PLV: 10%
Cost Estimates
We estimated lower- and upper-bound costs for physical inspections and two variants of PLV (renting and owning).
We calculated physical inspection costs in two components: cost per-chip and additional cost per cluster inspection:6
- Physical inspection cost per chip ($9–$48.80) depends on the salary of the tester, the time it takes to properly test each chip, and overhead time.
- Additional cost per physical cluster inspection ($2,590–$6,050) depends on the salary of the tester, travel time to the cluster, and travel expenses.
We calculated a single all-in cost for each of the two PLV options: renting PLV and owning PLV. These costs are annual and should scale linearly with the duration of the location verification program.7 For owning PLV, we amortize the cost of purchasing hardware over a five-year program. Renting PLV has a similar lower-bound cost estimate to owning PLV, but renting PLV has a much higher upper-bound estimate.
- Renting PLV cost ($2,592,987–$72,427,200) depends on the cost of renting central processing units (CPUs) and hardware security modules (HSMs), the cost of maintenance, the cost of setting the PLV standard, and firmware development costs.
- Owning PLV cost ($3,093,801–$28,805,814) depends on the cost of purchasing CPUs and HSMs, the co-location data center costs (i.e., space, energy, bandwidth), the cost of maintenance, the cost of setting the PLV standard, and the firmware development costs.
Results
Physical inspections did not have more detections-per-cost than renting or owning PLV in any of the 10.5 million scenarios we simulated. Because the model outputs a lower-bound and upper-bound for detections-per-cost, instead of a single estimate, we compare location verification approaches by comparing their detections-per-cost ranges. When a method’s entire detections-per-cost range is above the other’s, that method outperforms the other one. When the ranges partially or fully overlap, the two methods tie.
PLV strictly outperformed physical inspections in all scenarios with a large number of clusters, but no input variable cleanly separated PLV wins from ties. In other words, although we identified conditions that were sufficient for PLV to win outright, those conditions were not necessary: PLV still strictly outperformed physical inspections in many scenarios where they were not met.
Renting PLV strictly outperformed physical inspections in all scenarios in which there were more than 18,000 clusters, including all scenarios in which clusters containing only ten chips were included in the cluster mix.8 Overall, renting PLV strictly outperformed physical inspections in the vast majority of scenarios, and in the remaining fraction of scenarios, the two methods tied. Furthermore, compared to the median lower-bound estimate of detections-per-cost for physical inspections, the median lower- and upper-bounds for renting PLV were 7x and 205x higher, respectively (Table 1).
Owning PLV strictly outperformed physical inspections in all scenarios in which there were more than than 11,000 clusters, including all scenarios where clusters containing only ten chips were included in the cluster mix.9 Overall, owning PLV strictly outperformed physical inspections in the vast majority of scenarios, and in the remaining fraction of scenarios, the two methods tied. Furthermore, compared to the median lower-bound estimate of detections-per-cost for physical inspections, the median lower- and upper-bounds for owning PLV were 18x and 172x higher, respectively (Table 1).
While both renting and owning PLV outperformed physical inspections on detections-per-cost, owning PLV strictly outperformed physical inspections in more scenarios than renting PLV did. The high cost of renting HSMs was primarily responsible for the significantly higher upper-bound cost of renting PLV than owning PLV. This does not allow us to definitively conclude, however, that owning PLV is better than renting it, as can be seen in Table 1 where the median upper bound for renting is higher than for owning.
Conclusions
As the total number of export-controlled chips increases, PLV dominates physical inspections under a greater number of scenarios because the cost of PLV is amortized over a greater number of chips. In practice, this means that the baseline model (i.e., accounting for the current number of export-controlled chips in circulation) is likely the most favorable that physical inspections will appear relative to PLV. As more controlled chips are exported in the future, the detections-per-cost gap between PLV and physical inspections will continue to increase.
The most effective location verification approach would likely involve a PLV system that is supplemented by small numbers of physical inspections. While our model suggests that scaling up physical inspections is less cost-effective than PLV, the two methods have distinct comparative advantages, which can still complement one another.
Specifically, PLV may further increase the effectiveness of standard BIS inspections of AI chip clusters (i.e., end use physical inspections). An inspection regime that only involves physical inspections incentivizes smugglers to divert parts of clusters, as doing so would reduce the likelihood of detection. If BIS were to introduce PLV, it would create an opposing incentive for smugglers to divert entire clusters because PLV would likely detect the diversion of partial clusters anyway. This, in turn, increases the effectiveness of low-volume physical inspections and limits the options available for smugglers to divert chips. Together, PLV and physical inspections could better deter both partial cluster diversion and whole cluster diversion.
Appendix A: Model Steps
- Build viable mixes of cluster sizes and counts: Take the cartesian product (i.e., all possible ordered combinations) of different mixes of cluster size and count assuming a fixed number of tracked chips.10
- Build scenarios: There will be a scenario for each combination of (a) cluster mix (from the previous step), (b) different number of chips diverted per cluster size, (c) probability of individual check success for PLV, (d) probability of individual check success for physical inspections, and (e) different number of chips tested per cluster size.11 Each scenario will have one row per scenario component, which refers to the number of clusters of a unique size, as defined by the scenario mix (e.g., four clusters with 100,000 chips each could be one scenario component).
- Estimate detections by PLV and physical inspections: For each cluster component of each scenario (i.e., each cluster size), record the number of diverted chips that the system is expected to detect. This value is the probability of detection multiplied by the number of diverted chips in the cluster. We calculate detection probability using a hypergeometric distribution.12
- Aggregate cluster components into one row per scenario.
- Calculate cost for each scenario:
- Calculate the upper and lower bounds on cost.
- Calculate the upper and lower bounds of detections-per-cost: the expected number of detected (diverted) chips divided by cost in dollars
- Assign a code for the relationship between physical inspection and PLV for detections-per-cost:
- Physical max < PLV min
- Physical max is within PLV range and Physical min < PLV min
- Physical min and max are both within PLV range
- Physical min is within PLV range and Physical max > PLV max
- Physical min > PLV max
- Physical min < PLV min and Physical max > PLV max
- Count the number of scenarios that have each relationship code.
Appendix B: Model Constants
We performed some sensitivity checks using six mix increments (17%) instead of the seven mix increments (14%) used in the final model. Scenarios derived from six mix increments appear to be, on average, less favorable toward PLV than scenarios derived from seven mix increments; PLV options strictly dominate fewer scenarios by 2–5 percentage points. Therefore, six mix increments are an ideal testbed because they take less time to compute and can even give us an early warning whether the model is sensitive to the variable under test. Still, we use seven mix increments in the final model because we feel that six mix increments do not create enough scenarios (i.e., 3.8 million instead of 10.5 million).
1. Total Number of Tracked Chips
The baseline model assumes three million tracked chips.
Using Epoch AI Chip Owners data, as of Q4 2025, 2.36 million data center AI chips have been sold since 2022 excluding (a) those sold to China and (b) those owned by U.S.-headquartered cloud service providers or other U.S. hyperscalers.13 This subset of Epoch AI’s data only includes the following four families of data center AI chips: Nvidia graphics processing units (GPUs), AMD Instinct GPUs, Google tensor processing units (TPUs), and Amazon Trainium application-specific integrated circuits (ASICs). Therefore, this count misses GPUs sold by other companies like Cerebras, SambaNova, and Intel. In addition, Epoch AI’s Chip Owners and Chip Sales datasets are incomplete before 2024, meaning that they may undercount AI chip sales from 2022 and 2023. Furthermore, by the time a location verification program would start, the total number of AI chips would have increased further. Therefore, we round up to three million chips. This assumes that BIS would require location verification for controlled chips that have already been sold.14
Sensitivity: As the total number of export-controlled chips increases, PLV dominates physical inspections under a greater number of scenarios because the cost of PLV is amortized over a greater number of chips. Therefore, the baseline model is likely the most favorable the analysis will ever look for physical inspections. When we increase the total number of chips from three million to 10 million, the share of scenarios where PLV strictly dominates physical inspections increases by 8–9 percentage points.
2. Minimum Number of Clusters per Cluster Size
The baseline model requires the minimum number of clusters per cluster size specified in Table B1.
We use this constant to exclude mixes (i.e., different combinations of cluster sizes and counts that add up to a fixed number of tracked chips) that are incompatible with known data on GPU clusters. Epoch AI’s GPU Clusters15 and AI Data Centers16 datasets give us a lower bound on the number of clusters of various sizes that use export-controlled chips. We count these clusters and use them as a lower bound in the model. Functionally, this excludes mixes with zero count of specific cluster sizes.
Sensitivity: Epoch AI’s GPU cluster datasets do not have any clusters of 10–100 chips, as these datasets focus on large-scale clusters. Therefore, in the baseline model, we allow mixes to have zero ten-chip clusters. When we require at least one ten-chip cluster (with seven mix increments, that means at least 14% of chips must be in ten-chip clusters), PLV strictly outperforms physical inspections in all scenarios. This means that all of the scenarios in the baseline model where PLV does not strictly outperform physical inspections have zero ten-chip clusters.
3. Minimum Number of Chips Diverted per Cluster
The baseline model assumes a minimum of 100 chips diverted per cluster, except that scenario components with no diversion (K = 0) and full diversion (K = N) are always allowed.
Because we assume that smuggling will not always involve diversion of the entire cluster (although we do include such scenarios), setting a minimum of 100 diverted chips allows us to ignore scenarios where only small numbers of chips are diverted. This excludes, for example, any scenario where fewer than 100 chips would be diverted from a cluster of 100,000 chips.
We suspect that smugglers would be inclined to divert small clusters entirely but only fractions of large clusters. This is, in part, because larger clusters are more likely to be audited than smaller clusters, so smugglers may seek to avoid detection through partial diversion of large clusters, as well as be more willing to fully divert small clusters that are less likely to be inspected.
Sensitivity: What if the minimum number of diverted chips per cluster component is decreased from 100 to 10, re-allowing scenarios that we judged were not viable? With six mix increments, changing the variable as specified increases the number of scenarios from 3.8 million to 10.2 million. One percentage point of scenarios move from ties to a strict PLV win. Therefore, our cost model is not sensitive to changes in the minimum number of diverted chips per cluster.
4. Minimum Number of Chips Diverted per Scenario
The baseline model assumes that at least 114,000 chips must be diverted across the entire scenario.
Since our model is static (i.e., evaluates PLV and physical inspections on fixed, potential states of the world), this constant should be a lower-bound estimate of smuggled, controlled AI chips to date.17 We considered a few options (Table B2) and ultimately chose to sum the 2024 and 2025 estimates from Epoch AI for a minimum of 114,000 chips smuggled in 2024 and 2025.18
Sensitivity: We also tested a minimum number of 500,000 chips diverted per scenario, which decreases the number of scenarios from 10.5 million to 3.5 million. The share of scenarios in each bucket moved by no more than one percentage point. Therefore, our cost model is not sensitive to an increase in the minimum number of diverted chips per scenario.
5. Minimum Number of Tests
The baseline model assumes that a minimum of one chip must be tested (using physical inspections) across the entire scenario. Therefore, the baseline scenario excludes unrealistic scenarios where zero chips are physically inspected.
Sensitivity: With a minimum of 500 chips tested per scenario, the share of scenarios in each bucket moved by less than one percentage point. Therefore, our cost model is not sensitive to an increase in the minimum number of tests per scenario.
6. Number of Physical Inspections per Cluster per Year
The baseline model assumes that if a cluster size is supposed to receive physical inspections (per the scenario) that it is randomly inspected twice per year.
We believe that conducting physical inspections once per year is insufficient because if smuggling occurs the day after a physical inspection is conducted, BIS would be unaware of this for a year. Increasing the frequency to twice per year allows BIS to identify diversion earlier. Physically inspecting a cluster more than twice per year may be unfeasible, given the number and geographic distribution of clusters, the limited number of inspectors, and the disruption of a proper inspection on data center operations.
Sensitivity: With only one physical inspection per year, the number of scenarios that PLV strictly wins drops by 19 and 5 percentage points for renting and owning PLV, respectively. Physical inspections still did not have more detections-per-cost than renting or owning PLV in any of these scenarios. Conversely, more frequent inspections (i.e., three per year) increases the costs of physical inspections and subsequently increases the share of scenarios where renting and owning PLV outperform physical inspections from 86% and 92% to 88% and 96%, respectively. Therefore, our cost model is not sensitive to decreases or increases in the frequency of physical inspections.
7. PLV Value Discount Multiplier
The baseline model assumes that a diverted chip detected by PLV is worth half as much as a diverted chip detected by a physical inspection. This means the baseline model applies a discount multiplier of 0.5 to PLV detections-per-cost.
This constant is multiplied by PLV detections-per-cost to reduce PLV’s value relative to physical inspections. We do not assign the same value to detecting potential diversion with PLV vs. physical inspection because physical inspections provide more detailed information and are more likely to directly prove that diversion has occurred. Furthermore, PLV detection will likely have a higher false-positive rate than physical inspections.19 Therefore, we assume that a PLV detection is worth half as much as physical inspection detection.
Sensitivity: We tested PLV discount multipliers of 0.5, 0.25, 0.05, and 0.01. It takes a discount multiplier of 0.01 for physical inspections to strictly outperform both PLV approaches in a greater number of scenarios. Therefore, for physical inspections to become the better location verification option, the value of PLV detecting diversion must be 100x worse than a physical inspection detecting diversion.
8. Probability That a Diverted Chip Is Not Detected by a Physical Inspection
The baseline model assumes that when a physical inspection is performed on a chip that has been diverted, there is a 5% probability the inspection will fail to detect that the chip has been diverted.
Increasing this failure rate simulates an adversary tricking physical inspections more frequently. We set this as a low percentage because we assume physical inspections involve properly attesting GPU authenticity (reducing false negatives), as opposed to just inspecting serial numbers or packaging.
Sensitivity: We did not test the sensitivity of this parameter since the model already favors PLV and increasing this probability would cause PLV to strictly outperform physical inspections in even more scenarios.
9. Probability That a Diverted Chip Is Not Detected by PLV
The baseline model assumes that when the PLV system pings a chip that has been diverted, there is a 10% probability the inspection will fail to detect that the chip has been diverted.
A successful detection means either (a) the chip does not respond and U.S. export control authorities suspect the lack of response indicates diversion or (b) the chip does respond and shows the chip in an unauthorized location. Therefore, unsuccessful detection means either (a) the chip does not respond and U.S. export controls authorities do not suspect the lack of response indicates diversion or (b) the chip does respond and shows the chip in an authorized location. Increasing the failure rate simulates an adversary tricking PLV with greater frequency.
Sensitivity: What if bad actors can break the PLV system very easily? How unreliable would PLV need to be for physical inspections to be better? We find that the model results are not sensitive to PLV failure rate. PLV needs to fail 99.999% of the time (five nines) for physical inspections to strictly outperform both PLV approaches in a greater number of scenarios. Even with a high failure rate per chip, PLV is testing every chip, and you only need to detect a single diverted chip to detect a cluster-wide issue. For example, if the PLV system only successfully geolocates one chip out of a 1,000 chip cluster, if that one chip is diverted, then the entire cluster is flagged (which negates the failure of the PLV system on the remaining 999 chips). However, if a bad actor can compromise the PLV system at scale, they may be able to deterministically obfuscate the locations of entire chip clusters. Should this occur, physical inspections would very likely become the better location verification option.
- “Geolocation” refers to mechanisms that use data generated by chips, servers, and data center infrastructure to periodically identify and verify their locations.
- We use detections-per-cost instead of net value because we could not confidently convert the number of diverted chips detected by a location verification method into a dollar value. Doing so would require us to model two additional parameters: (1) the percentage of diversion that has already been detected by U.S. law enforcement—for which location verification does not add value—and (2) the dollar value of detecting that a chip has been diverted, which in most cases means the chip cannot be recovered by U.S. law enforcement.
- We consider some levels of diversion to be unviable for certain cluster sizes. For example, we do not consider scenarios where only one chip is diverted from a 100,000 chip cluster (see Appendix B.3 for more details). We also consider scenarios where there are clusters that experience no diversion.
- If the scenario dictates that a cluster of a certain size would experience diversion, only one cluster or up to the specified share of clusters in that component (whichever is higher) will experience the prescribed level of diversion (K); all other clusters of the same size experience no diversion.
- We do not consider it viable to test more than 10,000 chips per cluster, therefore such scenarios’ components are omitted.
- Our calculations for physical inspection cost are available in this Google Sheets workbook: https://docs.google.com/spreadsheets/d/1jz9wlM0gWkwgCuqucfysz3Iy9UF-vnBHUDxVp3ViNAw/edit?gid=515843759#gid=515843759.
- Our calculations for PLV cost are available in this Google Sheets workbook: https://docs.google.com/spreadsheets/d/1am0WdvZpuFG6utIuAuhwEXTmKz95NnN2xk1jcVQl2g8/edit?gid=1039123233#gid=1039123233.
- When size-ten chip clusters are included in the cluster mix, a minimum of 14% of all chips are allocated to size-ten clusters.
- When size-ten chip clusters are included in the cluster mix, a minimum of 14% of all chips are allocated to size-ten clusters.
- Example mix: ID: ClusterMix_N10-C131240_N100-C4286_N1000-C429_N10000-C43_N100000-C4 Description: 131240x(N=10) + 4286x(N=100) + 429x(N=1000) + 43x(N=10000) + 4x(N=100000).
- We need to generate different scenarios for the number of chips tested, instead of just picking the number of chips tested that maximizes detections-per-cost, because detections-per-cost depends on the number of diverted chips per cluster, which is unknown to BIS.
- “Hypergeometric Distribution,” Wolfram MathWorld, accessed July 10, 2026, https://mathworld.wolfram.com/HypergeometricDistribution.html [https://perma.cc/3HXZ-3NH3].
- “AI Chip Owners,” Epoch AI, accessed July 8, 2026, https://epoch.ai/data/ai-chip-owners?tab=count. All chips in the Epoch estimate (2.36 million) should be export-controlled. Breaking down the “Other” owners category by chip type demonstrates that the included types are: B300, B200, H100/H200, A100, and “Other AMD GPUs.” All are export-controlled except, potentially, for “Other AMD GPUs.” Epoch’s methodology shows that the oldest data center GPU included in their estimates is MI250X, which is subject to U.S. export controls. Therefore, all GPUs in the estimate are export-controlled.
- For an analysis of the feasibility of activating a PLV system for chips that have already been manufactured and exported, see section “Enabling PLV on the Chip” in Jacob Feldgoise, Kyle Miller, and Hanna Dohmen, (Center for Security and Emerging Technology, September 2026), https://cset.georgetown.edu/publication/tracking-ai-chips.
- “GPU Clusters,” Epoch AI, accessed September 16, 2026, https://epoch.ai/data/gpu-clusters.
- “AI Data Centers,” Epoch AI, accessed September 16, 2026, https://epoch.ai/data/ai-data-centers.
- This model does not account for the fact that some percentage of diversion has already been detected by U.S. law enforcement. Accounting for this would reduce the detections-per-cost of physical inspections by either the same factor or a larger factor relative to PLV. Most known diversion involves smuggling complete clusters. If the remaining undetected cases of diversion involve smuggling of partial clusters, that would differentially benefit PLV because it is better suited to detecting partial diversion. In either case, accounting for already-detected diversion should not change the outcome of the model.
- We chose the Epoch AI estimate for 2024, even though the CNAS estimate is lower, because Epoch’s analysis is more recent and may account for chips smuggling that was not yet discovered when the CNAS report was published.
- While the false-positive rate for physical inspections is likely lower than for PLV, it is not zero. An AI chip selected for physical inspection may not be in its expected data center because it has been removed for legitimate reasons; the chip may have been temporarily removed for maintenance, moved to a different cluster for legitimate reasons, or decommissioned.