Executive Summary
It is indisputable that AI chips are being diverted to unauthorized countries, including China. While the exact volume of diversion remains unknown, it nonetheless risks undermining U.S. export controls designed to prevent adversaries from developing and deploying advanced AI capabilities. Location verification—which would allow regulators to determine where AI chips are located—has emerged as a key proposal to strengthen export control enforcement efforts. We assess which types of location verification methods merit consideration, how much they would cost, what their limitations are, and what policy design choices policymakers should weigh. Ultimately, our analysis suggests that location verification could be deployed for a feasible but non-trivial cost and would enhance U.S. export control enforcement efforts by generating leads and imposing costs on chip smugglers. However, location verification mechanisms have significant shortcomings that limit their effectiveness and ultimate net value, and we believe those shortcomings have received insufficient attention to date. We aim to articulate the limitations clearly to help policymakers make informed judgments about whether and how to pursue such mechanisms.
A centralized, ping-based location verification (PLV) system—supplemented by physical inspections to investigate leads—would offer the most robust and feasible approach to location verification. We evaluated location verification methods based on four criteria: verifiability, accuracy, security, and repeatability. Based on these criteria, we determine that PLV and physical inspections are the most feasible methods. PLV specifically is more robust than other geolocation mechanisms, inventory management tools, mail-in inspections, and video inspections. PLV, relative to physical inspections, is more cost-effective and scales better in the long term as more chips are deployed.
If policymakers pursue location verification, regulators should initially prescribe a flexible location verification approach, where each responsible entity implements their preferred form of location verification to allow industry to develop, test, and evaluate solutions. After a testing period, the Bureau of Industry and Security (BIS) can mandate the approach(es) it deems most suitable or maintain a flexible approach.
To mitigate the potential for noncompliance, regulators should also centralize responsibility for reporting when a given chip is outside of its intended location; this means a single entity (i.e., BIS itself, the chip designers, or trusted third parties) would be responsible for knowing the intended location of each chip and verifying its location, even if the chip changes hands multiple times. Beyond reporting responsibility, we recommend that a BIS-certified trusted third party operate the infrastructure of the PLV system (i.e., landmark and reporting servers) to avoid conflicts of interest.
Our cost modeling confirms that a PLV system is more cost-effective than physical inspections, and PLV could be deployed for a feasible but non-trivial cost, depending on implementation. The potentially government-borne costs would represent 0.5% to 7.2% of BIS’s FY2026 budget if landmark servers are owned or 0.3% to 25.7% if they are rented. Across more than ten million simulated scenarios, physical inspections never achieved higher detections-per-cost than a PLV system, whether the landmark servers are owned or rented. We estimate that a PLV system would cost roughly $3.1 million to $28.8 million annually if the landmark servers are owned and $2.6 million to $72.4 million annually if they are rented.
Policymakers should have clear expectations of what a PLV system can and cannot achieve, as any PLV system will have significant limitations. Most importantly, a PLV system can only detect diversion after it has already occurred. We identify five additional limitations:
- Enabling a PLV system on AI chips in circulation: For software or firmware implementations of PLV, the system could be enabled on AI chips that have already been manufactured and are in circulation, but doing so would require compliance from each end user who would need to install an update. Hardware implementations of PLV could not be enabled on chips in circulation.
- Connectivity between chips and landmark servers: When a controlled AI chip fails to respond to a PLV system, the system cannot inherently know whether it is due to diversion or legitimate reasons. Chips that remain offline—whether because they are in storage, in transit, or deliberately disconnected by bad actors—produce ambiguity in the system.
- Adversarial location obfuscation: Well-resourced adversaries could trick a PLV system into reporting that a smuggled chip is still in a permitted location. Even a PLV system designed with prudent security measures could be subverted, and as a result some percentage of chips that report being in their intended locations may actually have been diverted.
- Approximate geolocation of AI chips: By positioning one landmark server in every major data center hub—defined as an area containing a large concentration of data centers within a 19-mile radius—outside the United States, China, and Russia, PLV could likely achieve country-level accuracy (an error-circle radius of 116 miles) for the vast majority of PLV-tracked chips. But even in the best case, the accuracy of a PLV system would highly likely be no better than about 20 miles, meaning that the system cannot reliably distinguish locations between nearby data centers operated by different entities. This may be particularly problematic in areas with a high density of data centers, as well as border regions near restricted locations such as China.
- End-user obfuscation: Because PLV systems verify locations rather than end user identities, the system cannot detect diversion to an unauthorized user where the chip’s physical location remains unchanged.
Whether the benefits to U.S. export control enforcement efforts justify the costs will also depend on a series of policy design choices. For each policy design choice, we outline the trade-offs for each question and make a recommendation to aid policymakers in their decision-making. First, we recommend that PLV be implemented with firmware-based signing, as it best balances robustness against adversarial attack, cost, and ease of implementation. Second, we recommend that location verification be required only for data center chips subject to the most stringent licensing requirements to align with current export control objectives. Third, we recommend that BIS-certified trusted third parties operate the landmark and reporting servers in order to eliminate conflicts of interest and leverage private sector expertise. Fourth, we believe the program should aim to detect diversion globally (rather than only to countries of concern) as the additional costs are marginal. Lastly, policymakers also have to consider whether domestically deployed chips are tracked as well, which may require Congress to grant BIS additional authorities.
A U.S. government indictment regarding AI chip smuggling demonstrates the potential benefits and limits of a PLV system. While the PLV system could not have prevented the initial diversion of AI chips to China, it may have alerted U.S. officials to the scheme earlier, potentially helping the government disrupt the operation more quickly. This example highlights that BIS also needs to receive alerts when chips are slow to activate, not just when chips are detected outside of permitted locations.
To fully realize the benefits of a PLV system, BIS must be adequately resourced. Before pursuing any kind of location verification, policymakers should ensure that BIS has sufficient resources and staffing to pursue the leads that such a system would generate. It is well-established that BIS faces resource constraints; therefore, the utility of a PLV system is limited by BIS’s capacity to pursue those leads. A recent request to increase BIS’s budget to $450 million for FY2027 would be a positive development, but if BIS enforcement remains seriously resource-constrained, the value of PLV-generated leads will be partially undermined by BIS’s capacity challenges.