01 / The mechanism and its boundary
What is being described
CNAS describes itself as an independent, bipartisan, nonprofit organization that develops national security and defense policies S-3612. Its 2024 report Secure, Governable Chips, by Aarne, Fist and Withers, proposes on-chip mechanisms for governing AI chips S-0056:
- Hardened security module. The report proposes a module that enforces valid firmware and up-to-date operating licenses and supports remote attestation, rolled out in stages from firmware changes to tamper-evident and then tamper-proof hardware S-0056. See Hardware-enabled guarantees (flexHEG) and guarantee processors, Hardware performance throttling and licensing and TEE remote attestation for AI workloads.
- Hardening and effort. It judges that existing on-chip features must be hardened before they can be relied on in adversarial settings, and estimates that leading firms could build the required functionality with 18 months to 4 years of effort S-0056.
- Location verification. It illustrates ping-based checks with a landmark server in Paris: a reply within 9 ms would place a chip inside a circle that excludes countries subject to export restrictions S-0056. It expects hundreds of landmarks worldwide S-0056. See Chip location verification.
- Ownership tracking. It writes that on-chip mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and know-your-customer policies S-0056; see Chip registries and manufacturing records.
A 2025 CNAS working paper by Grunewald, of IAPS, and Fist estimates that between 10,000 and several hundred thousand AI chips, with a median estimate of about 140,000, may have been smuggled to China in 2024 S-3382. It recommends that chip designers implement software-based location verification, and that the US Bureau of Industry and Security require notification of exports, re-exports and ownership transfers of controlled AI chips S-3382.
Connections in the research map
Related research
Sources and provenance
- S-3612 / Tier B
Center for a New American Security: Mission ↗
· 2026 · Center for a New American Security
Supports: independent bipartisan nonprofit producing national-security and defense policy
Version and catalogue details - S-0056 / Tier B
Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗
O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security
Supports: Secure, Governable Chips: security module, staged rollout, hardening, development effort, location verification, ownership tracking
Version and catalogue details - S-3382 / Tier B
Countering AI Chip Smuggling Has Become a National Security Priority ↗
E. Grunewald, T. Fist · 2025 · Center for a New American Security (working paper)
Supports: 2025 working paper: smuggling estimate for 2024; recommended location verification and notification of exports and ownership transfers
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review