Built in a day, this is my project submission for BlueDot Impact’s Breaking Barriers to AI Safety Hackathon in SF, where it won first place. Some added context in my LessWrong post. — Edward Paulino
Frontier AI development runs on compute. A simple formula is that more chips make more powerful models. In the AI race between the US and China, we can think of compute as the fuel. Operating under the premise that China narrowing the gap in AI capabilities with the US would be destabilizing, chips smuggled into China are a problem.
US officials claim DeepSeek trained a model on several thousand smuggled Blackwell chips at a data center in Inner Mongolia. They allege that the chips traveled inside servers initially sold to approved countries, then crossed the border in pieces. While Nvidia has denied this happened, nobody can actually prove it which is a symptom of the broader problem.
FIG. 01 — THE SMUGGLING ROUTE
FACTORY
→
APPROVED BUYER
→
DISMANTLED SERVERS
→
INNER MONGOLIA
These smuggled chips pose another risk. For any future worldwide compute agreement, where both sides monitor each other’s activities, unknown “shadow” chips are a liability. China can allow inspections and monitoring of its legitimate chips, but the possibility of a hidden, off-the-grid data center somewhere compromises the deal. Verifiability is the foundation of any agreement.
So when it comes to selling compute to the rest of the world, Washington faces two bad options. Refuse to sell, and the compute-starved middle countries buy into and fuel China’s growing chip industry. Or sell freely, and risk creating a chip pipeline straight to China.
But this is a false dilemma. Instead of viewing chip controls as binary on/off, there is a third way that creates some much-needed flexibility.
The solution:Licensing enforced by the chip itself
Imagine that every chip ships with a hardware device that enforces a compute budget that counts down as the chip runs. Renewing this budget would require a cryptographic signature “key” from an authorized party. If you don’t obtain a new key, your chip stops working. This is the licensing mechanism.
In this way, it doesn’t matter how many times the chip switches hands or where in the world it happens to be. Using the chip with no way to get a new license is like driving a car with a proprietary fuel cap you can’t open.
FIG. 02 — THE BUDGET LIFECYCLE
1 — CHIP SHIPS
BUDGET FULL — SIGNED
2 — GAUGE DRAINS WITH USE
COUNTING DOWN
3 — TWO ENDINGS
SIGNED RENEWAL → RUNNING
NO SIGNATURE → BRICK
The mechanism is offline licensing, built on a flexible hardware-enabled guarantee, or flexHEG: a small guarantee processor sealed inside a tamper-respondent enclosure.
This is the technology that enables turning the crude on/off switch of export controls into more of a dial. That’s the “flexible” part of the design. Regulators can size compute budgets so exported chips serve, for example, business or consumer needs, but stay below frontier-training scale.
It’s worth noting that this implementation of flexHEG preserves privacy. The chip never reports what you run because it has no awareness of the data being processed. This approach has its tradeoffs. On one hand, this licensing does not prevent chips from being clustered together and achieving compute thresholds necessary for model training. On the other hand, a chip that countries view as a glorified wiretap for US snooping is not going to be very popular, if not outright prohibited.
One catch is that most of this technology doesn’t exist at a significant scale. While Nvidia has built location verification technology as an optional software feature it’s piloting, the on-chip licensing mechanism does not exist beyond prototypes. No one has built it at industrial scale. This is unlikely to change until there is a compelling reason for chipmakers to do so. A key objective of this plan is to outline how to optimally develop this reason.
The plan:Leveraging the export carrot
The two sides are talking past each other. Nvidia has said no backdoors, no kill switches, no spyware. That’s the literal title of their press release. It knows customers bristle at the idea of losing any amount of control of their chips. They know attaching strings of any sort, no matter the privacy and security guarantees, is incredibly unpopular. Washington, meanwhile, won’t widen access to chips that can just walk across borders without a care in the world.
Here’s how to break the stalemate. The Commerce Department has the authority to publish a license exception. It could create a streamlined process where chips with certified hardware guarantees may be exported to the Gulf states, Southeast Asia, and the forty-odd countries treated as transshipment suspects. Ungoverned chips would face the same restrictions they face today. China remains a separate decision for later, perhaps under some broader agreement.
There is precedent for this bargain with middle countries. Nations that want civilian nuclear technology accept safeguards and inspections as the price of entry. In many ways, compute is this era’s nuclear material: beneficial in the right circumstances but potentially dangerous without safeguards.
An astute reader would point out a problem mentioned earlier: this technology does not exist beyond prototypes. The strategy is that the new export rule creates a massive incentive for a chipmaker to develop the compliant chip and reap the rewards of an expanded market. Nvidia data center GPUs, for example, already contain per-chip identity keys and telemetry capability, the basic building blocks flexHEG requires. This approach aligns incentives, capability, and resources in a compelling way.
Here’s another carrot. Chipmakers are already experimenting with hardware as a service. Nvidia recently launched a revenue-sharing cloud program with initial commitments of up to 210,000 GPUs. It has spent years blurring the line between selling chips and renting them, from DGX Cloud’s training-as-a-service model to subscription software like AI Enterprise. Chip licensing is a tempting opportunity: lower upfront prices for customers in exchange for a recurring revenue stream.
Without the significant research and development capacity of chipmakers behind the effort, progress is uncertain. Researchers behind the flexHEG estimate that a secure, on-chip version is a multi-year engineering effort beyond the capacity of philanthropy alone. These efforts have produced early prototypes funded by roughly $4 million in grants, and a pilot or two, but more is needed.
Creating the standard
Rather than inventing a standard from scratch, Commerce can adapt the design requirements already laid out in the public flexHEG and RAND research, which specify auditable, open-source mechanisms. A published rule need only establish the required capabilities and the testing regime, with certification performed by independent evaluators under the same third-party framework BIS uses for its most recent export licenses.
This approach outlines a plausible scenario taking actors “as they are”. It assumes that chipmakers want to increase profits, that middle countries want access to compute, and that the US wants to prevent an adversary’s access to resources that increase competition. It does not require the daunting prospect of passing legislation through Congress. It leverages a technology that has been demonstrated but not yet scaled. It creates a framework that can shift in response to future developments in algorithmic progress or geopolitics.
FIG. 04 — TIMELINE
YEAR 0 RULE PUBLISHED
YEAR ~3 FIRST GOVERNED SILICON SHIPS
YEAR 5 AND BEYOND GOVERNED SHARE RISING
Regulators can draft and implement the rule in a few months. The first governed chips may ship in roughly three years. Once implemented, the scale of governed silicon chips can be further modified via policy.
Existing ungoverned inventory
The millions of ungoverned GPUs already in the field are indeed a challenge. One potential solution would be to buy them out of circulation. Commerce and chipmakers could pair the license exception with a trade-in program, swapping old hardware for discounted governed chips with more compute and continued support. This could be better than retrofitting governance onto less valuable hardware never designed for it, retains customers in the chipmakers’ ecosystem, and steadily shrinks the pool of chips susceptible to smuggling.
Potential challenges
The following are load-bearing assumptions whose failure would compromise the plan’s likelihood of success.
Tamper resistance against state-level adversaries is unproven. Chip enclosures that can be defeated to steal keys compromise the entire licensing regime.
Middle countries must keep preferring governed American compute to ungoverned Chinese compute, a prospect that diminishes over time as Chinese compute performance improves.
Buyers may reject a renewable budget signed abroad as a foreign off-switch on mission-critical national infrastructure.
Chipmakers won’t commit multi-year engineering budgets to a license exception the next administration or news cycle can jeopardize.
Whoever signs renewals holds real power over other countries’ compute. Credible key governance plans may need to include multi-party quorums and open-source auditability.
A trade-in program can shrink but not eliminate the ungoverned compute supply, which remains a smuggling and agglomeration risk for the useful life of those chips.
More information would decrease uncertainty along many of these dimensions. However, one clear constant working against the effort in general is time. Capabilities progress, ungoverned chip proliferation, and geopolitical dynamics will all continue to advance, perhaps in unpredictable or unexpected ways. All factors that favor taking action sooner than later.
The flexHEG future
Someday, after a capability jump or a warning shot, governments, frontier labs, and society might want better control over the world’s AI compute. A US-China agreement to slow down is not entirely out of the picture. The feasibility of such an agreement depends on creating a foundation of compute verification. This plan outlines one possible strategy to make this possible.
About the author
Edward Paulino writes about government, technology, and building a better future. Views expressed are my own.
Sources
Trends in Artificial IntelligenceEpoch AIThe scaling premise: training with more compute has consistently produced more capable models, with frontier training compute growing about 5× per year.
Statement on UAE and Saudi Chip ExportsU.S. Department of Commerce · Nov 20, 2025Gulf access today: per-deal authorizations for G42 and HUMAIN, each with negotiated security conditions.
IAEA Safeguards Agreements at a GlanceArms Control Association · reviewed Nov 2024The nuclear precedent: NPT non-nuclear-weapon states accept comprehensive safeguards and inspections in exchange for peaceful nuclear technology.
New Funding Round on Hardware-Enabled Mechanisms (HEMs)Longview Philanthropy · Apr 30, 2025Source of the effort estimate: many person-years of development, with production versions expected to come from major chipmakers.