Built in a day, this is my project submission for BlueDot Impact’s Breaking Barriers to AI Safety Hackathon in SF, where it won first place. Some added context in my LessWrong post. Edward Paulino

A workable blueprint for a chip licensing regime

Practical steps to end chip smuggling

For policymakers: download the one-pager.

The problem: Compute fuels the AI race

Frontier AI development runs on compute. A simple formula is that more chips make more powerful models. In the AI race between the US and China, we can think of compute as the fuel. Operating under the premise that China narrowing the gap in AI capabilities with the US would be destabilizing, chips smuggled into China are a problem.

US officials claim DeepSeek trained a model on several thousand smuggled Blackwell chips at a data center in Inner Mongolia. They allege that the chips traveled inside servers initially sold to approved countries, then crossed the border in pieces. While Nvidia has denied this happened, nobody can actually prove it which is a symptom of the broader problem.

FIG. 01 — THE SMUGGLING ROUTE
FACTORY
APPROVED BUYER
DISMANTLED SERVERS
INNER MONGOLIA

These smuggled chips pose another risk. For any future worldwide compute agreement, where both sides monitor each other’s activities, unknown “shadow” chips are a liability. China can allow inspections and monitoring of its legitimate chips, but the possibility of a hidden, off-the-grid data center somewhere compromises the deal. Verifiability is the foundation of any agreement.

So when it comes to selling compute to the rest of the world, Washington faces two bad options. Refuse to sell, and the compute-starved middle countries buy into and fuel China’s growing chip industry. Or sell freely, and risk creating a chip pipeline straight to China.

But this is a false dilemma. Instead of viewing chip controls as binary on/off, there is a third way that creates some much-needed flexibility.

The solution: Licensing enforced by the chip itself

Imagine that every chip ships with a hardware device that enforces a compute budget that counts down as the chip runs. Renewing this budget would require a cryptographic signature “key” from an authorized party. If you don’t obtain a new key, your chip stops working. This is the licensing mechanism.

In this way, it doesn’t matter how many times the chip switches hands or where in the world it happens to be. Using the chip with no way to get a new license is like driving a car with a proprietary fuel cap you can’t open.

FIG. 02 — THE BUDGET LIFECYCLE
1 — CHIP SHIPS
BUDGET FULL — SIGNED
2 — GAUGE DRAINS WITH USE
COUNTING DOWN
3 — TWO ENDINGS
SIGNED RENEWAL → RUNNING
NO SIGNATURE → BRICK

The mechanism is offline licensing, built on a flexible hardware-enabled guarantee, or flexHEG: a small guarantee processor sealed inside a tamper-respondent enclosure.

This is the technology that enables turning the crude on/off switch of export controls into more of a dial. That’s the “flexible” part of the design. Regulators can size compute budgets so exported chips serve, for example, business or consumer needs, but stay below frontier-training scale.

It’s worth noting that this implementation of flexHEG preserves privacy. The chip never reports what you run because it has no awareness of the data being processed. This approach has its tradeoffs. On one hand, this licensing does not prevent chips from being clustered together and achieving compute thresholds necessary for model training. On the other hand, a chip that countries view as a glorified wiretap for US snooping is not going to be very popular, if not outright prohibited.

One catch is that most of this technology doesn’t exist at a significant scale. While Nvidia has built location verification technology as an optional software feature it’s piloting, the on-chip licensing mechanism does not exist beyond prototypes. No one has built it at industrial scale. This is unlikely to change until there is a compelling reason for chipmakers to do so. A key objective of this plan is to outline how to optimally develop this reason.

The plan: Leveraging the export carrot

The two sides are talking past each other. Nvidia has said no backdoors, no kill switches, no spyware. That’s the literal title of their press release. It knows customers bristle at the idea of losing any amount of control of their chips. They know attaching strings of any sort, no matter the privacy and security guarantees, is incredibly unpopular. Washington, meanwhile, won’t widen access to chips that can just walk across borders without a care in the world.

Here’s how to break the stalemate. The Commerce Department has the authority to publish a license exception. It could create a streamlined process where chips with certified hardware guarantees may be exported to the Gulf states, Southeast Asia, and the forty-odd countries treated as transshipment suspects. Ungoverned chips would face the same restrictions they face today. China remains a separate decision for later, perhaps under some broader agreement.

There is precedent for this bargain with middle countries. Nations that want civilian nuclear technology accept safeguards and inspections as the price of entry. In many ways, compute is this era’s nuclear material: beneficial in the right circumstances but potentially dangerous without safeguards.

An astute reader would point out a problem mentioned earlier: this technology does not exist beyond prototypes. The strategy is that the new export rule creates a massive incentive for a chipmaker to develop the compliant chip and reap the rewards of an expanded market. Nvidia data center GPUs, for example, already contain per-chip identity keys and telemetry capability, the basic building blocks flexHEG requires. This approach aligns incentives, capability, and resources in a compelling way.

Here’s another carrot. Chipmakers are already experimenting with hardware as a service. Nvidia recently launched a revenue-sharing cloud program with initial commitments of up to 210,000 GPUs. It has spent years blurring the line between selling chips and renting them, from DGX Cloud’s training-as-a-service model to subscription software like AI Enterprise. Chip licensing is a tempting opportunity: lower upfront prices for customers in exchange for a recurring revenue stream.

Without the significant research and development capacity of chipmakers behind the effort, progress is uncertain. Researchers behind the flexHEG estimate that a secure, on-chip version is a multi-year engineering effort beyond the capacity of philanthropy alone. These efforts have produced early prototypes funded by roughly $4 million in grants, and a pilot or two, but more is needed.

Creating the standard

Rather than inventing a standard from scratch, Commerce can adapt the design requirements already laid out in the public flexHEG and RAND research, which specify auditable, open-source mechanisms. A published rule need only establish the required capabilities and the testing regime, with certification performed by independent evaluators under the same third-party framework BIS uses for its most recent export licenses.

None of this needs new law or a vote in Congress. Commerce wrote and enacted its last major chip rule in five weeks, and it already conditions export licenses on independent third-party testing.

FIG. 03 — THEORY OF CHANGE
01
Rule published
02
Chipmakers develop and build governed silicon for access to global market
03
Middle markets access compute in western ecosystem
04
Hardware-enabled compute governance capacity expands significantly

This approach outlines a plausible scenario taking actors “as they are”. It assumes that chipmakers want to increase profits, that middle countries want access to compute, and that the US wants to prevent an adversary’s access to resources that increase competition. It does not require the daunting prospect of passing legislation through Congress. It leverages a technology that has been demonstrated but not yet scaled. It creates a framework that can shift in response to future developments in algorithmic progress or geopolitics.

FIG. 04 — TIMELINE
YEAR 0
RULE PUBLISHED
YEAR ~3
FIRST GOVERNED SILICON SHIPS
YEAR 5 AND BEYOND
GOVERNED SHARE RISING

Regulators can draft and implement the rule in a few months. The first governed chips may ship in roughly three years. Once implemented, the scale of governed silicon chips can be further modified via policy.

Existing ungoverned inventory

The millions of ungoverned GPUs already in the field are indeed a challenge. One potential solution would be to buy them out of circulation. Commerce and chipmakers could pair the license exception with a trade-in program, swapping old hardware for discounted governed chips with more compute and continued support. This could be better than retrofitting governance onto less valuable hardware never designed for it, retains customers in the chipmakers’ ecosystem, and steadily shrinks the pool of chips susceptible to smuggling.

Potential challenges

The following are load-bearing assumptions whose failure would compromise the plan’s likelihood of success.

More information would decrease uncertainty along many of these dimensions. However, one clear constant working against the effort in general is time. Capabilities progress, ungoverned chip proliferation, and geopolitical dynamics will all continue to advance, perhaps in unpredictable or unexpected ways. All factors that favor taking action sooner than later.

The flexHEG future

Someday, after a capability jump or a warning shot, governments, frontier labs, and society might want better control over the world’s AI compute. A US-China agreement to slow down is not entirely out of the picture. The feasibility of such an agreement depends on creating a foundation of compute verification. This plan outlines one possible strategy to make this possible.

About the author

Edward Paulino writes about government, technology, and building a better future. Views expressed are my own.

Sources
  1. Trends in Artificial Intelligence Epoch AI The scaling premise: training with more compute has consistently produced more capable models, with frontier training compute growing about 5× per year.
  2. Exclusive: China’s DeepSeek trained AI model on Nvidia’s best chip despite US ban, official says Reuters · Feb 24, 2026 The official claim: Blackwells likely clustered at DeepSeek’s data center in Inner Mongolia.
  3. DeepSeek reportedly using thousands of smuggled Nvidia chips for AI training The Decoder · Dec 10, 2025 Summarizes The Information’s investigation: servers bought legally in Southeast Asia, dismantled, moved through customs, reassembled in China.
  4. Nvidia decries ‘far-fetched’ reports of smuggling in face of DeepSeek training reports Tom’s Hardware · Dec 2025
  5. Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items from Export Controls RAND, working paper WR-A3056-1 · 2024 Origin of the offline-licensing approach: renewable, cryptographically signed limits on exported AI hardware.
  6. Flexible Hardware-Enabled Guarantees, reports I–III flexheg.com · 2025 Specifies the architecture: a guarantee processor inside a tamper-respondent secure enclosure.
  7. Nvidia’s new software could help trace where its AI chips end up CNBC · Dec 11, 2025 The location-verification pilot: opt-in software that estimates a chip’s country from network latency. Read-only, no kill switch.
  8. No Backdoors. No Kill Switches. No Spyware. NVIDIA Blog · Aug 5, 2025
  9. Export Administration Regulations, 15 CFR Part 740: License Exceptions eCFR The standing authority under which Commerce publishes license exceptions by rule, without new legislation.
  10. Statement on UAE and Saudi Chip Exports U.S. Department of Commerce · Nov 20, 2025 Gulf access today: per-deal authorizations for G42 and HUMAIN, each with negotiated security conditions.
  11. Administration Policies on Advanced AI Chips Codified Mayer Brown · Jan 2026 Documents new license requirements for roughly forty countries assessed as diversion risks to China.
  12. IAEA Safeguards Agreements at a Glance Arms Control Association · reviewed Nov 2024 The nuclear precedent: NPT non-nuclear-weapon states accept comprehensive safeguards and inspections in exchange for peaceful nuclear technology.
  13. Confidential computing on NVIDIA H100 GPUs for secure and trustworthy AI NVIDIA Developer Blog · 2023 Today’s shipping security features: on-die root of trust, secure and measured boot, signed attestation.
  14. Nvidia launches revenue-sharing AI cloud financing Data Center News · Jul 3, 2026 The launch commitments: Sharon AI up to 40,000 GB300 GPUs, Firmus up to 170,000, together the 210,000 figure.
  15. New Funding Round on Hardware-Enabled Mechanisms (HEMs) Longview Philanthropy · Apr 30, 2025 Source of the effort estimate: many person-years of development, with production versions expected to come from major chipmakers.
  16. SFF-2024: Mechanisms for Flexible Hardware-Enabled Guarantees (flexHEGs) Survival and Flourishing Fund · 2024 The grant round behind today’s prototypes: $4.1 million across nine flexHEG projects.
  17. Revision to License Review Policy for Advanced Computing Commodities Federal Register · effective Jan 15, 2026 The rule itself, containing the independent third-party testing condition on license applications.
  18. Trump greenlights Nvidia H200 sales to China if U.S. gets 25% cut CNBC · Dec 8, 2025 Start of the five-week clock: policy announced Dec 8, 2025; the rule above took effect Jan 15, 2026.
  19. BIS Revises Export Review Policy for Advanced AI Chips Destined for China and Macau Morgan Lewis · Jan 2026
  20. Nvidia Shipped 3.76 Million Data-center GPUs in 2023, According to Study HPCwire · Jun 10, 2024 TechInsights shipment data behind “millions”: 3.76 million data-center GPUs in 2023 alone, with about four million more projected for 2024.