Policy brief 20 · Cyber / Bio / Kinetic

Chip Registry

Know who controls America's largest AI supercomputers.

The chips that train the most powerful AI are export-controlled and worth smuggling: federal cases since 2025 involve hundreds of millions of dollars' worth bound for China. Yet no law requires anyone to report owning a large cluster of them, or to say when one changes hands. Congress should register the largest clusters, track every change of control, and verify that the chips are where the records say.

The Problem

Advanced AI chips are, in one federal prosecutor's words, "the building blocks of AI superiority."1 Exporting them to China requires a license,2 and smugglers are testing the rule. In October 2025, a Texas company and its owner pleaded guilty to smuggling after exporting or trying to export at least $160 million in Nvidia's advanced H100 and H200 chips.1 In March 2026, prosecutors charged three people, including a co-founder of a U.S. server maker, with diverting at least $510 million in AI servers to China over a few weeks in 2025; those charges are allegations.2

Federal law has barred flying an unregistered aircraft since 1958, and the FAA records sales and leases down to large engines.3 A data center full of export-controlled AI chips needs no registration at all.

Washington has tried. A 2023 executive order directed Commerce to require anyone acquiring a large computing cluster to report its existence and location;4 it was revoked in January 2025.5 A 2024 proposal to make U.S. cloud providers verify foreign customers' identities was withdrawn in December 2025.6 Three weaknesses keep the chips hard to follow:

  1. Fronts do the buying. Four people charged in November 2025 allegedly used a Tampa company called Janford Realtor, which "was never involved in any real estate transactions," to buy Nvidia chips for shipment to China through Malaysia and Thailand.7
  2. Paper trails get forged. In the $160 million case, the owner and others falsified shipping paperwork to hide where the chips were going.1
  3. Inspections get fooled. The March 2026 indictment alleges the defendants staged thousands of non-working "dummy" servers, swapping serial-number stickers with a hair dryer, to pass a company audit and a Commerce Department inspection.2

Why legislation: Export law already governs chips that leave the country,8 and the House Foreign Affairs Committee voted 42–0 for the Chip Security Act, which would require location verification on exported chips and let Commerce keep a record of each one's location and end user.9 At home, no statute requires a record of the largest clusters, and an executive order can be undone by the next one. Congress should set the registry's purpose and its limits in law. A nation that polices these chips abroad should know where they are at home.

The Solution

A three-step staircase: each step stands alone, and each step up adds certainty about where the chips are. Scope: facilities and holdings above a capacity threshold, set by rule after a technical review, so that only clusters able to train frontier models are covered; phones, gaming PCs, and ordinary business servers are excluded. Export controls are addressed separately.

Step 1 — Register the largest clusters. Owners and operators above the threshold file a confidential registration with Commerce: legal owner, ultimate controlling parent, operator, location, equipment type, total capacity, and a compliance contact. Capacity split among affiliates under common control counts together, so no one ducks the line by carving up a cluster; ordinary cloud customers owe no filing, and the rules say so plainly. Entries stay confidential, access is logged, only totals are published, and the registry holds no customer data or model content. A bipartisan 2024 Senate bill would have required large AI data centers to report their location and owner.10

Step 2 — Track every change of hands. Report installations, capacity changes, sales, leases, changes of control, and retirements promptly. Buyers and sellers both report, and Commerce matches the records, so chips that vanish between filings stand out; chips ordered are tracked apart from chips installed. The FAA already records aircraft sales this way.3 A registry is only as good as its last update.

Step 3 — Verify the location. Require covered chips sold into registered facilities to support location verification, the feature the Chip Security Act would require on exports and the 2025 AI Action Plan asks Commerce to explore.11 Commerce may spot-check that registered chips are where the registry says. A dummy server cannot answer a location check.

Where to start: Step 1 is the floor: a confidential filing, updated yearly. Step 2 is the heart of the proposal, because only a current record can catch a diversion.

Administration and enforcement: Commerce keeps the registry, with NIST technical support and coordination with Customs. Proposed rules within a year; first filings six months after final rules. Correction notices and civil penalties for missed filings, with stiffer penalties for concealment. Registration grants no permission to train or deploy anything.

Risks and Mitigations

  • A target for spies: A list of America's largest clusters is a prize for foreign intelligence. Collect the minimum, separate sensitive fields, limit and log access, and test the system's security independently; a breach remains a serious risk.
  • Surveillance creep: A registry of hardware must never become monitoring of people. The statute excludes consumer devices and all customer and model content, bars unrelated uses, and requires legal process for any inspection beyond records.
  • Evasion: Smugglers can stay below any threshold, and foreign clusters are out of reach. The registry targets concentrations large enough to matter, the threshold updates with technology, and aggregation rules catch deliberate splitting.

Similar Bills

Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.

Federal

Proposal or bill Relevant provisions and fit Fit
H.R. 3447 — Chip Security Act
Huizenga (R-MI), Foster (D-IL) + 41 cosponsors; Senate companion S. 1705, Cotton (R-AR) + 21 cosponsors
Ordered reported with a substitute (42–0) · Mar. 26, 2026
§4(a) requires location verification on advanced chips before export; §4(c) lets Commerce keep a record of each exported chip's "location and current end-user." Direct precedent for Step 3 and for Step 2's record; covers exports only. Compares introduced text; the substitute was not reviewed. High
S. 5616 — Preserving American Dominance in Artificial Intelligence Act of 2024
Romney (R-UT), Reed (D-RI), Moran (R-KS), King (I-ME), Hassan (D-NH)
118th Congress · Introduced Dec. 19, 2024; expired
§8(a) requires owners of AI data centers above 10²⁰ operations per second to report each facility's location and owner; §5(b)(1) requires chip sellers and cloud providers to collect foreign customers' identity, location of use, and beneficial ownership. Direct precedent for Step 1; no tracking of transfers. High
Export Control Reform Act of 2018
Pub. L. 115-232, div. A, title XVII, subtitle B
Enacted Aug. 13, 2018
Existing authority for export licensing, recordkeeping, and enforcement; the basis of the March 2026 charges. Foundation for export-side records; no domestic inventory. Partial
S. 2938 — Artificial Intelligence Risk Evaluation Act of 2025
Hawley (R-MO), Blumenthal (D-CT), Blackburn (R-TN)
Referred to committee · Sept. 29, 2025
§5(c)(2)(C) directs DOE to propose "automated and continuous monitoring of AI hardware usage" and cloud deployments. A related oversight direction; creates no registry. Related

State

No state has enacted a registry of AI chips or computing clusters, and chip exports are a federal matter. The one close state proposal found is California's vetoed SB 1047.

Proposal or bill Relevant provisions and fit Fit
California — SB 1047 (2024)
Vetoed · Sept. 29, 2024
Proposed §22604 required computing-cluster operators to verify customers able to train large models, record identity and payment details, keep records for seven years, and keep a shutdown capability. Identifies users of compute rather than owners of chips; never became law. Partial

What this adds: The Chip Security Act tracks chips that leave the country, and the 2024 Senate bill would have listed large data centers once. This proposal keeps a current, confidential record of who owns and controls the largest clusters at home, reconciles every transfer, and verifies location, with privacy limits written into the statute.

Notes

  1. U.S. Department of Justice, "'Operation Gatekeeper' Disrupts Trafficking Network and Seizes More Than $50 Million in Advanced GPUs Destined for China and Other Restricted Locations," December 8, 2025. Quotation from U.S. Attorney Nicholas J. Ganjei (S.D. Tex.). A Houston-area company and its owner pleaded guilty on October 10, 2025; court documents describe at least $160 million in Nvidia H100 and H200 GPUs exported or attempted and falsified shipping paperwork. ↩ ↩2 ↩3

  2. U.S. Department of Justice, "Three Charged with Conspiring to Unlawfully Divert Cutting Edge U.S. Artificial Intelligence Technology to China," March 19, 2026 (S.D.N.Y. indictment). Alleges about $2.5 billion in server purchases in 2024–2025 and at least about $510 million diverted "between late April 2025 and mid-May 2025 alone." The defendants are presumed innocent. ↩ ↩2 ↩3

  3. 49 U.S.C. § 44101(a) ("a person may operate an aircraft only when the aircraft is registered"), derived from the Federal Aviation Act of 1958; 49 U.S.C. § 44107(a) (recording of conveyances, and of leases and security instruments for engines of at least 550 rated takeoff horsepower). ↩ ↩2

  4. Executive Order 14110, § 4.2(a)(ii), 88 Fed. Reg. 75191, 75197 (Oct. 30, 2023). Owners were to report "the existence and location of these clusters and the amount of total computing power available in each cluster." ↩

  5. Executive Order 14148, § 2(ggg), 90 Fed. Reg. 8237 (Jan. 20, 2025). ↩

  6. Office of Information and Regulatory Affairs, Unified Agenda entry, RIN 0694-AJ35, Fall 2025. The notice of proposed rulemaking (89 Fed. Reg. 5698, Jan. 29, 2024) would have required U.S. providers of cloud computing to verify foreign customers; listed as "Withdrawn 12/16/2025." ↩

  7. U.S. Department of Justice, "U.S. Citizens and Chinese Nationals Arrested for Exporting Artificial Intelligence Technology to China," November 20, 2025 (M.D. Fla. indictment). The charges are allegations. ↩

  8. Export Control Reform Act of 2018, 50 U.S.C. § 4801 et seq. (Pub. L. 115-232, Aug. 13, 2018). ↩

  9. H.R. 3447, Chip Security Act, 119th Cong. § 4(a), (c) (introduced text); bill status: ordered reported in the nature of a substitute, 42–0, March 26, 2026. The substitute was not reviewed. ↩

  10. S. 5616, Preserving American Dominance in Artificial Intelligence Act of 2024, 118th Cong. § 8(a) (introduced text; expired). Sponsored by Sen. Romney (R-UT) with Sens. Reed (D-RI), Moran (R-KS), King (I-ME), and Hassan (D-NH). ↩

  11. The White House, America's AI Action Plan, July 2025, p. 21 ("explore leveraging new and existing location verification features on advanced AI compute"). ↩