Introduction: The Chip That Had to Come Home Before It Could Leave
Start with an H200.
It is a rectangle of engineered silicon roughly the size of a paperback book once mounted on its board, and it is one of the most consequential manufactured objects of the decade. Its logic die is fabricated in Taiwan by TSMC, the culmination of a supply chain that reaches through Dutch lithography machines, Japanese photoresists, and American design software. Its high-bandwidth memory depends on an East Asian semiconductor ecosystem dominated by SK Hynix, Samsung, and Micron. Its architecture was conceived by Nvidia, an American corporation headquartered in Santa Clara, California. And, as of 2026, one of its most eager potential customers sits in Beijing, Hangzhou, or Shenzhen.
Yet before this chip can legally participate in Chinese AI infrastructure under the regime that took shape in January 2026, something remarkable must happen. A chip fabricated in Taiwan must first travel to the United States, where it undergoes independent third-party security and performance testing on American soil.[1,2] Its exporter must certify to the Bureau of Industry and Security that domestic supply is sufficient, that no American customer is being displaced, that the Chinese recipient maintains security and know-your-customer procedures, and that remote-access safeguards are in place.[3,4] A 25 percent tariff mechanism, constructed under Section 232 of the Trade Expansion Act of 1962, attaches a fiscal toll to the transaction.[3] Only then — license granted, testing complete, revenue share settled, conditions accepted — may the chip depart for China. And upon arrival it faces a second gate entirely: Beijing’s own import approvals, quotas, and conditions, granted company by company and still being negotiated as this paper goes to press.[17,20]
The chip, in other words, has effectively acquired something it never needed during the era of ordinary globalization:
A geopolitical passport.
Here is the paradox that motivates this paper. A semiconductor does not vote. It has no nationality in any human sense. It holds no opinions about the balance of power in the Taiwan Strait. But in the AI economy of 2026, its performance tier, its physical location, its destination, its owner, and even its computational purpose increasingly determine what governments will allow it to do — and what price the world must pay for the privilege. The H200 is not merely traded; it is adjudicated. It is not merely sold; it is admitted, conditioned, tolled, tested, and tracked. That is the transition from semiconductor commerce to sovereign compute allocation.
And that is where Accelerator Seigniorage begins.
Why This Paper Is Called “Accelerator Seigniorage”
The title deserves a deliberate defense, because it makes a strong claim by analogy, and analogies in political economy should be earned rather than asserted.
Seigniorage is one of the oldest concepts in monetary economics. In its classical form, it describes the value captured by a sovereign through its privileged role in issuing money: the difference between the face value of coinage and the cost of the metal and minting, or, in the modern fiat context, the real resources a government acquires by issuing currency that costs almost nothing to produce. Seigniorage exists because the sovereign occupies a position no private actor can replicate. Only the state can declare what counts as legal tender within its borders; therefore only the state can harvest the rent embedded in that declaration. The privilege is not primarily about producing anything. It is about controlling access to something everyone else needs and cannot mint for themselves.
This paper argues that advanced AI accelerators have acquired a structurally comparable characteristic. Because only a handful of firms and countries can design, fabricate, package, supply, or lawfully authorize frontier AI hardware, the governments that sit astride those chokepoints can extract fiscal, geopolitical, informational, and jurisdictional rents from access to compute. The United States does not manufacture the H200 in any complete sense — Taiwan fabricates it, Korea supplies its memory — but the United States controls the design ecosystem, the export jurisdiction, the software stack, and, increasingly, the legal architecture through which the chip may circulate. Like a mint, Washington produces something scarce not by smelting it but by authorizing it. The license is the coin.
Hence the formal definition that anchors everything that follows:
Accelerator Seigniorage is the economic, strategic, informational, and jurisdictional value captured by a state through its ability to authorize, condition, route, verify, restrict, or monetize access to advanced artificial-intelligence accelerators.
The crucial distinction between this concept and the traditional vocabulary of trade policy can be stated in two questions. Traditional export control asks: Can this chip be sold? It is a binary inquiry, answered yes or no, embargo or commerce. Accelerator Seigniorage asks a different and far richer question: Under what price, route, performance level, security conditions, verification regime, jurisdiction, and political bargain may this chip be used? The first question produces walls. The second produces tollbooths, meters, passports, escrow arrangements, revenue shares, testing laboratories, and diplomatic concessions. The first is the logic of denial. The second is the logic of the mint.
If this argument is right, then the world is not moving along the simple axis that most commentary assumes — from free trade toward ever-tighter embargo. It is instead moving through a more interesting sequence:
Free Trade → Export Control → Selective Licensing → Conditional Access → Monetized Access → Verified Compute
Each stage of that sequence preserves the coercive core of the prior stage while adding a new instrument on top of it. Licensing did not abolish the embargo on frontier chips; it created a category of permitted exceptions beneath the frontier. Monetization did not abolish licensing; it attached a price to the license. Verification, still embryonic, will not abolish monetization; it will make the entire structure auditable, and therefore durable. The story of 2022 to 2026, told properly, is the story of a state discovering — partly by design and partly by improvisation — that a technological chokepoint can be operated the way a central bank operates a currency: as a continuous source of leverage, information, and revenue, rather than as a switch to be flipped once.
The remainder of this paper develops that argument in ten movements. It first establishes the empirical chronology, because the sequence of events between October 2022 and August 2026 is itself the strongest evidence for the thesis. It then traces the intellectual shift from embargo to tollbooth (Section 1), examines the H200 episode as the founding precedent of the new regime (Section 2), and constructs the paper’s signature framework: the five forms of Accelerator Seigniorage (Section 3). Section 4 asks why the corporations subjected to this regime have largely tolerated it. Section 5 models the smuggling economics that shadow every licensing decision. Section 6 globalizes the argument, showing how the same architecture operates through security alignment in the Gulf rather than revenue extraction in China. Section 7 connects the phenomenon to the five-layer structure of the AI economy. Section 8 confronts the strongest counterargument — the Seigniorage Paradox — and Section 9 translates the analysis into the political questions that should be asked before the November 2026 midterms. Section 10 distills seven pillars of lessons learned, and the conclusion returns, as it must, to the chip that had to come home before it could leave.
The Chronology:
Concepts in political economy live or die on their evidence, and the evidence here is unusually clean, because the policy record between 2022 and 2026 is dense, public, and datable almost to the day. What follows is the skeleton of that record; the sections that follow put flesh on it.
October 2022. The Biden administration established sweeping controls intended to restrict China’s access to advanced computing chips, supercomputer components, and semiconductor-manufacturing capabilities — the most aggressive technology-denial regime imposed on a major economy since the Cold War. According to Chris Miller of Tufts University, whose 2022 book Chip War became the canonical account of the industry’s geopolitics, the driving conclusion inside the National Security Council was that advanced chips would drive progress in artificial intelligence, and that AI progress had direct military consequence.[11,14] The controls were strengthened and their performance thresholds recalibrated in October 2023, closing workarounds that Nvidia had engineered into China-specific products.
April 2025. The second Trump administration informed Nvidia that exports of its China-oriented H20 accelerator — a product deliberately designed beneath the control thresholds — would themselves require licenses. Nvidia recorded a $4.5 billion charge in its first quarter of fiscal 2026 for excess H20 inventory and purchase obligations, and told investors the restrictions would cost approximately $8 billion of revenue in the following quarter.[21] For a moment, the policy trajectory looked like a straight line toward total denial.
August 2025. The line bent. In an arrangement first reported by the Financial Times and confirmed by the White House, Nvidia and AMD agreed to remit 15 percent of revenue from specified China chip sales — the H20 and the MI308 respectively — to the U.S. government in connection with the granting of export licenses.[5,6] The deal was negotiated personally between President Trump and Nvidia chief executive Jensen Huang, reportedly down from an initial 20 percent ask.[6] Corporations do not ordinarily pay the federal government a share of export revenue; export licenses do not ordinarily carry fees at all.[5] Legal scholars and trade experts immediately described the arrangement as unprecedented and possibly unlawful — an export tax in all but name, in apparent tension with the Constitution’s Export Clause.[7] The seigniorage era had begun, whether or not anyone yet called it that.
December 8, 2025. President Trump announced that the United States would permit exports of the H200 — a far more capable chip than the H20, roughly six times its total processing performance — to “approved customers” in China, in exchange for 25 percent of the revenue accruing to the U.S. government.[1,4] The announcement landed, with almost novelistic timing, on the same day federal prosecutors unsealed a smuggling case involving $160 million of diverted H100 and H200 hardware.[44]
January 13–15, 2026. The Bureau of Industry and Security issued and published a final rule converting the license review policy for H200-class exports to China and Macau from a presumption of denial to case-by-case review — conditioned on certifications of sufficient U.S. supply, protection of American customers against displacement, security and know-your-customer procedures at the Chinese recipient, remote-access safeguards, and independent third-party testing conducted in the United States before export.[1,2,3,4] Chips fabricated in Taiwan would first ship to the United States for screening. Blackwell-generation products remained under presumption of denial.[44]
January 14, 2026. The White House, completing a Section 232 national-security investigation into semiconductors, imposed a 25 percent tariff on a narrow class of advanced computing chips — the H200 and AMD’s MI325X among them — when imported under covered circumstances, with broad exclusions for chips supporting U.S. datacenters, domestic manufacturing, research and development, startups, and other approved American applications.[3] The distinction matters and recurs throughout this paper: the 2025 arrangement resembled a license-linked revenue payment; the 2026 mechanism was structured as an import tariff layered onto the physical routing requirement, rather than a naked export tax.
Late January 2026. Beijing constructed its own gate. Chinese customs authorities initially instructed agents that H200 chips were not permitted to enter the country, and regulators discouraged domestic purchases except where necessary, protecting the domestic semiconductor buildout.[17] Then, during Jensen Huang’s visit to China in the last week of January, Reuters reported that ByteDance, Alibaba, and Tencent had been approved to purchase more than 400,000 H200 chips collectively, with other firms queuing for subsequent rounds and DeepSeek receiving conditional approval days later.[17,18] Chinese customers had by then placed orders for more than two million H200s — far beyond Nvidia’s available inventory.[20]
May–June 2026. Enforcement caught up with liberalization. On May 31, Commerce moved to close a loophole through which the most advanced Nvidia and AMD hardware — Blackwell- and Rubin-class processors never licensed for China — had reportedly been reaching foreign subsidiaries of Chinese companies, including operations in Malaysia, potentially in the hundreds of thousands of units.[35,36] Malaysian customs, having tightened its own transshipment controls, seized 72 servers containing advanced AI chips worth roughly $13 million at Kuala Lumpur airport on June 5.[33,34] Reporting the previous summer had already revealed that U.S. authorities were embedding hidden location trackers in selected high-risk server shipments as an investigative technique against suspected diversion.[31,32]
July 14, 2026. The system became operational — barely. Under Secretary of Commerce for Industry and Security Jeffrey Kessler told the House Foreign Affairs Committee that licensed H200 shipments to China had begun but remained minimal.[15,16]
“The bottom line is very few shipments against licenses for H200s and equivalents have taken place.”
— Jeffrey Kessler, Under Secretary of Commerce for Industry and Security [15]
August 6, 2026. The administration invoked Section 232 again — this time for polysilicon and its derivatives, the strategic input at the base of both the solar and semiconductor supply chains — imposing a 15 percent tariff and a minimum-import-price structure, with onshoring incentives that waive the duties for companies building American production capacity.[25,26,27] The polysilicon proclamation is the strongest single piece of evidence that the H200 mechanism is not an isolated Nvidia arrangement but part of a broader movement: the fusion of national security, industrial policy, and revenue-producing trade controls into a single instrument class.
Four years, then, from embargo to auditable, tolled, dual-sovereign, conditionally licensed commerce. No single traditional category — export control, tariff policy, industrial policy, sanctions law — adequately describes the composite. That is precisely why a new term is needed.

Section 1: From Embargo to Tollbooth
The history of AI-chip controls is routinely narrated as a straight line toward tighter prohibition: each rule stricter than the last, each loophole closed harder than the one before. The record examined in this paper tells a different story. It is a history of policy experimentation — of a state testing, discarding, and recombining instruments in real time, under commercial pressure from the most valuable company in the world and strategic pressure from its principal geopolitical rival. Understanding why the experiments moved in the direction of the tollbooth, rather than the wall, requires beginning with the original security logic and the ways technology itself undermined it.
1.1 The Original Security Logic
The October 2022 controls concentrated on three targets: advanced computing chips above defined performance thresholds, supercomputer end uses, and the semiconductor-manufacturing equipment and know-how needed to produce advanced chips domestically. The policy logic was primarily capability denial. If artificial intelligence progress is a function of computational scale — and the empirical scaling literature of the early 2020s suggested it overwhelmingly was — then constraining China’s access to the computational substrate would slow its military modernization, its frontier AI development, and its supercomputing programs simultaneously. The chip was treated the way enriched uranium is treated: as a dual-use input whose mere accumulation constitutes strategic risk.[11,14]
It is worth pausing on how radical this was as trade policy. The 2022 rules did not sanction a company for misconduct or respond to a specific violation. They restricted an entire civilization-scale economy’s access to a general-purpose technology on the theory of what that technology might eventually enable. In doing so, Washington converted commercial semiconductor performance metrics — total processing performance, interconnect bandwidth, memory bandwidth — into instruments of national security law. Engineering specifications became legal categories. That conversion, more than any particular threshold, is the seed from which Accelerator Seigniorage grew, because once a performance number is a legal boundary, everything about that boundary — who sits on which side, at what price, under what conditions — becomes a political variable that a sovereign can manage.
1.2 The Technological Adaptation Problem
Controls written as performance thresholds immediately create incentives for manufacturers to redesign hardware around those thresholds — and that makes export controls on semiconductors unusual among trade instruments, because the controlled object itself is a moving target that responds to the regulation. The dynamic runs as a loop, and between 2022 and 2025 the loop completed several full cycles:
Government writes a performance threshold. Engineers redesign around it — Nvidia’s A800 and H800, and later the H20, existed for no other reason. Government revises the threshold, as it did in October 2023. Industry modifies the product again. Meanwhile, on the other side of the wall, China improves domestic alternatives — Huawei’s Ascend line, Cambricon’s accelerators — and the global research community makes software radically more efficient, so that each unit of restricted hardware yields more intelligence per watt and per dollar than the rule-writers assumed. The control system therefore does not sit above technological development; it interacts dynamically with it, and often loses ground to it.
The deeper problem is informational. A static embargo generates no information about the adversary’s demand, deployment, or dependence; it simply severs the relationship and blinds the regulator. A licensing system, by contrast, forces every would-be transaction through a government aperture, generating a continuous stream of intelligence about who wants what, in what quantities, for which datacenters, under which corporate structures. Part of the movement from embargo to tollbooth is the discovery that the tollbooth sees.
1.3 From H20 Prohibition to Licensed Commerce
Nvidia’s H20 experience demonstrated the commercial cost of total denial with brutal clarity. The H20 was itself an artifact of compliance — a deliberately degraded accelerator engineered beneath the 2023 thresholds specifically to preserve legal access to the Chinese market. When the April 2025 license requirement effectively halted its sale, Nvidia absorbed a $4.5 billion charge and warned of roughly $8 billion in forgone quarterly revenue.[21] But the company’s deeper argument, pressed in filings and in Jensen Huang’s relentless public advocacy, was not about a quarter’s revenue. It was that exclusion from China would strengthen competitors and allow rival hardware and software ecosystems — above all Huawei’s — to mature inside the largest pool of AI developers outside the United States, permanently forfeiting the ecosystem dependence that constituted America’s real leverage.[21]
This produces the paper’s first important paradox, which every subsequent section must carry as background:
The tighter an export embargo becomes, the greater the incentive for the sanctioned country to eliminate its dependence on the exporter.
An embargo is a wasting asset. Its coercive power is greatest on the day it is imposed and decays as the target substitutes away. A perfectly enforced, permanent embargo on AI chips would end not with Chinese capitulation but with a Chinese semiconductor industry that no longer needs anything Washington controls — at which point the chokepoint, and every form of leverage that flows from it, is gone. The strategic question was never whether denial imposed costs on China; it plainly did. The question was whether the rate at which denial slowed China exceeded the rate at which denial accelerated China’s substitution. By 2025, a growing faction in Washington — advancing what Taiwanese analysts described as the “theory of diffusion” — had concluded it did not.[13]
1.4 The Tollbooth Alternative
The alternative strategy that crystallized between August 2025 and January 2026 can be stated as a change of sentence. Instead of: “You cannot have American accelerators,” the policy became: “You may have selected American accelerators — but America determines the conditions of entry.”
Everything in this paper follows from that substitution. The wall becomes a gate; the gate acquires a tollkeeper; the tollkeeper acquires a ledger, a testing lab, a revenue account, and a set of diplomatic side-agreements. Denial is retained — for Blackwell, for military end users, for embargoed actors — but it becomes the top tier of a graduated structure rather than the structure itself. The state stops asking only what it can prevent and starts asking what it can charge, learn, and condition. This is the beginning of Accelerator Seigniorage: the moment the chokepoint stops being operated as a barricade and starts being operated as a mint.

Section 2: The H200 Precedent
If the framework of this paper survives, it will be because of what happened to a single product line in a single ninety-day window. The H200 episode — December 2025 through the spring of 2026 — is the empirical centerpiece of Accelerator Seigniorage, the first fully articulated instance of a state operating every instrument of the new regime at once: political authorization, conditional licensing, physical routing, mandatory testing, fiscal extraction, and, on the far side of the ocean, a mirrored gate operated by the rival sovereign. Each element deserves examination in turn.
2.1 December 2025: Political Authorization and the Management of Generational Distance
President Trump’s December 8 announcement authorized the export of the H200 — Nvidia’s second-most-powerful production accelerator at the time — rather than the frontier Blackwell and Rubin generations that American hyperscalers were deploying.[1,44] The choice of chip is more analytically important than the choice to sell at all, because it reveals the underlying doctrine: generational segmentation. China may gain access to powerful American computation while remaining structurally behind the current American frontier.
This concept rewards careful statement. Washington is not attempting to freeze China at a fixed capability level — an impossible task given domestic Chinese progress. It is attempting to manage the distance between technological generations: to ensure that whatever China buys legally is always one to two generations behind what America deploys, so that the gap itself becomes the protected asset. The policy resembles nothing so much as a franchise selling last season’s product line into a secondary market: revenue is harvested from the trailing edge while the leading edge remains exclusive. The reaction from the architects of the 2022 controls was immediate and furious. Former National Security Adviser Jake Sullivan, speaking to The New York Times, captured the denial school’s objection in a single line:[11]
“This decision is nuts. We are literally handing away our advantage.”
— Jake Sullivan, former U.S. National Security Adviser [11]
The counter-position, advanced by administration officials and sympathetic analysts, held that a China running on American silicon and American software is a China whose AI trajectory Washington can see, meter, and — if necessary — interrupt, whereas a China locked out entirely becomes a China running on Huawei, invisible and unleveraged. The Senate testimony of Chris Miller days before the announcement framed the underlying competition as a race across three inputs — power, talent, and computing capacity — with compute as the one arena of commanding American advantage; Miller himself warned against surrendering it.[13,14] The December decision, in other words, was not the product of consensus. It was a wager: that dependency is a stronger weapon than denial.
2.2 January 13: BIS Changes the Gate
The BIS final rule that operationalized the December announcement is far more sophisticated than a binary approved/denied register, and its architecture is worth dwelling on because it is, in embryonic form, a compute-admission system — the administrative skeleton of everything this paper predicts. Under the rule, qualifying license applications for advanced computing commodities below defined thresholds (total processing performance under 21,000 and total DRAM bandwidth under 6,500 GB/s, parameters that admit the H200 and MI325X while excluding Blackwell) move to case-by-case review only if the applicant satisfies conditions relating to:[2,3,4]
sufficient U.S. product availability, so that Chinese demand cannot cannibalize domestic supply; adequate foundry capacity, so that export volumes do not crowd out American allocation; security procedures and know-your-customer screening at the Chinese recipient; safeguards against unauthorized remote access to the exported computing power; and independent third-party performance and security testing conducted physically in the United States before the chips depart — which, for Taiwan-fabricated silicon, means the chip must come home before it can leave.[2,4] Reexports and transfers within China remain under presumption of denial; only direct exports from U.S. soil qualify — a jurisdictional design choice that guarantees American physical custody at the moment of decision.[3,44] Analyses of the rule and its accompanying policy indicated an effective volume architecture as well, limiting China-bound quantities relative to U.S. sales.[11,44]
Read as administrative law, this is a licensing rule. Read as political economy, it is an admissions office for computation: an applicant demonstrates worthiness across supply, security, identity, and verification dimensions, pays the toll, submits the hardware for inspection, and receives conditional entry for a defined performance class. No prior export-control regime for any commodity — not oil, not aircraft, not enriched uranium — has combined these particular elements in this particular way.
2.3 January 14: The Tariff Architecture
The following day’s Section 232 proclamation supplied the fiscal instrument. A 25 percent tariff attached to a narrow class of advanced computing chips — the H200 and MI325X among them — when imported under covered circumstances, with sweeping exclusions for chips destined for U.S. datacenters, domestic manufacturing, research, startups, and other approved American uses.[3] The design is ingenious and slightly disorienting: because the BIS rule requires China-bound chips to route physically through the United States for testing, the chips become imports before they become exports, and an import tariff can do the work of an export tax without colliding as directly with the Export Clause of the Constitution — the legal objection that had dogged the 15 percent arrangement of August 2025.[3,7] The 2025 deal looked like a license-linked revenue payment negotiated company by company; the 2026 mechanism is structured as generally applicable tariff law.
The important intellectual point is not the percentage. It is the combination. A single H200 transaction under the January regime simultaneously involves: an export license, U.S.-based third-party testing, an import tariff, an authorized and screened customer, security conditions at the destination, and a deliberately restricted technology generation. No single traditional trade-policy category — tariff, quota, embargo, sanction, licensing regime — adequately describes that composite. It is a new instrument class, and this paper’s contention is that it needs a new name.
2.4 China’s Counter-Gate and the Birth of Dual Sovereign Licensing
Then Beijing built the mirror image. China’s initial response to the H200 opening was not gratitude but customs instruction: agents were told the chips were not permitted to enter, and domestic companies were discouraged from purchasing them except when necessary, while regulators weighed how imports would interact with the state’s decade-long drive for semiconductor self-reliance.[17,20] Beijing reportedly discussed requiring firms to purchase quotas of domestic chips as a condition of receiving import approval — seigniorage’s mirror: access to foreign compute, tolled in units of loyalty to the domestic ecosystem.[17]
Then, in late January, the gate opened selectively. ByteDance, Alibaba, and Tencent received approval to purchase more than 400,000 H200s collectively, with conditions still being decided and other firms queuing; DeepSeek received conditional approval days later; by May, roughly ten Chinese companies had U.S. authorization with per-company caps reported around 75,000 units, routed partly through approved distributors such as Lenovo and Foxconn.[17,18,19,20] Chris Miller’s assessment of Beijing’s underlying posture remained the essential caution against reading the approvals as convergence:[12]
“The Chinese government is dead set on trying to build out its own chip ecosystem.”
— Chris Miller, Tufts University, author of Chip War [12]
The composite result is a phenomenon this paper names Dual Sovereign Licensing: an American chip destined for China now effectively requires permission from both Washington and Beijing — an export license and revenue arrangement on one side, an import approval with domestic-purchase conditions on the other. The manufacturer no longer controls market access by itself. Two sovereign governments do, each extracting its own form of seigniorage from the same transaction: Washington in dollars, testing custody, and information; Beijing in industrial-policy compliance and managed dependence. Kessler’s July testimony that actual shipments remained “trivial” despite licenses on both sides is the proof that the gates, not the market, now set the flow rate.[15,16] For the political economy of technology, this is an extraordinary transformation: the commodity has become a treaty instrument, and every shipment is a small act of diplomacy.

Section 3: The Five Forms of Accelerator Seigniorage
Monetary seigniorage is not one thing. Economists distinguish the direct fiscal revenue of currency issuance from the inflation tax, from the “exorbitant privilege” of reserve-currency status, from the informational advantages that flow through a currency’s payment rails. Accelerator Seigniorage decomposes the same way. The events of 2025 and 2026 reveal at least five distinguishable forms, each with its own mechanism and its own species of value captured by the state. This taxonomy is the signature framework of the paper.
| Form | Mechanism | Value Captured by Government |
| 1. Licensing Seigniorage | Permission to export specific accelerators to specific parties | Political leverage, negotiating currency, and potentially fiscal value |
| 2. Tariff Seigniorage | Duties and revenue shares applied through controlled trade routes | Direct Treasury revenue from geopolitical scarcity |
| 3. Custodial Seigniorage | Mandatory testing, physical routing, and jurisdictional custody | Control over the physical circulation of compute |
| 4. Verification Seigniorage | Location verification, reporting, screening, telemetry | Information and enforcement advantage |
| 5. Performance Seigniorage | Differentiating allowable chips from frontier chips | Preservation of technological distance |
3.1 Licensing Seigniorage
Scarcity transforms the license itself into something valuable — arguably into the most valuable single document in the AI economy. When Chinese customers have placed orders for more than two million H200s against an available inventory of roughly 700,000, and when only licensed transactions may proceed, the marginal license is worth the marginal chip’s entire scarcity premium.[20] An export license under these conditions ceases to resemble a regulatory formality and begins to resemble an economic concession — the way a nineteenth-century state granted railway concessions or mining rights. The state is not producing the GPU. It is producing the legal possibility of the GPU’s sale, and it controls access to the market in which that possibility can be exercised.
Licensing seigniorage is also the form most naturally converted into diplomacy, because a license can be granted, delayed, conditioned, or revoked with no legislative action and no announced price. The queue itself is leverage: every Chinese firm awaiting a subsequent approval round, every Gulf datacenter awaiting an allocation, is a supplicant whose behavior Washington can shape while the application pends. The regulator’s in-tray becomes an instrument of statecraft.
3.2 Tariff Seigniorage
This is the clearest fiscal component and the one that most directly justifies the monetary analogy: the state converts geopolitical scarcity into Treasury revenue. The August 2025 arrangement extracted 15 percent of H20 and MI308 China revenue; the January 2026 architecture attaches a 25 percent mechanism to the H200 class; the August 2026 polysilicon proclamation extends the same fusion of security and revenue — tariff plus minimum import price plus onshoring incentives — to a strategic input one layer down the supply chain.[5,25,26] At Reuters-reported pricing of roughly $27,000 per H200, the initially approved Chinese volume alone represented on the order of $11 billion of top-line sales — and a multi-billion-dollar claim for the U.S. government if converted to shipments at the announced percentage.[24]
But tariff seigniorage introduces the most dangerous question in this entire subject, and it belongs at the center of the paper rather than in a footnote: if restricting a technology produces government revenue, can the regulator remain indifferent between security and commerce? A pure security regulator wants risky transactions to equal zero. A revenue-participating regulator wants risky transactions to equal the maximum tolerable number. Those are different objective functions housed in the same building. Trade economists spotted the tension immediately; as Deborah Elms of the Hinrich Foundation put it when the 15 percent deal was announced:[10]
“If you have a 15% payment, it doesn’t somehow eliminate the national security issue.”
— Deborah Elms, Hinrich Foundation [10]
Peter Harrell of the Carnegie Endowment pushed the logic to its uncomfortable terminus — if security determinations carry a price, what, in principle, is unpriceable?[7]
“The Chinese would pay a lot for F35s and advanced US military technology, too.”
— Peter Harrell, Carnegie Endowment for International Peace [7]
The seigniorage framing does not resolve this conflict. It names it, and insists that any honest account of the new regime must carry it forward as a standing institutional hazard. Section 10 returns to it as Pillar Three.
3.3 Custodial Seigniorage
The requirement that Taiwan-fabricated chips travel to the United States for independent testing before continuing to China matters well beyond quality verification. It places the transaction — physically, not merely legally — within American jurisdiction at the decisive moment.[2,4] While the chip sits in a U.S. testing facility, it can be inspected, fingerprinted, serialized, delayed, or seized. Its itinerary becomes part of the regulation; its bill of lading becomes a compliance document. Geography itself becomes a control surface.
Custodial seigniorage is the least discussed and perhaps the most underrated of the five forms, because it converts the map into an instrument. A state that can dictate the route of a commodity can dictate the choke points at which every other instrument — tariff collection, verification, enforcement — operates. It is the difference between taxing a river’s trade and owning the only bridge. The historical rhyme is the medieval staple port: the crown designating the single town through which wool must pass so that it could be weighed, taxed, and observed. The January 2026 rule designates the United States itself as the staple port of frontier compute.
3.4 Verification Seigniorage
This is the most futuristic form, and the one whose infrastructure is being assembled in public view. The Chip Security Act — introduced in both chambers in May 2025, advanced 42–0 by the House Foreign Affairs Committee in March 2026, and endorsed in June 2026 by a coalition of verification-technology firms — would require covered integrated circuits to carry location-verification mechanisms within 180 days of enactment, with mandatory reporting to BIS when licensed chips appear outside approved locations, reach unauthorized users, or show evidence of tampering.[37,38,39] The technical research base has matured in parallel: the compute-governance literature identifies hardware as the uniquely governable input of AI development precisely because chips can verify and enforce rules about their own use, through delay-based location attestation, trusted execution environments, offline licensing, and workload metering — mechanisms that remain technically immature but are advancing from proposal to prototype.[40,47,48]
The direction of travel is unmistakable. Governments today know who bought the GPU. The verification regime under construction points toward a future in which governments know — continuously, cryptographically — where the GPU is operating, and eventually what class of work it is doing. The seigniorage captured here is informational: a standing map of the world’s licensed compute, updated in real time, visible to one sovereign. No commodity in economic history has carried its own audit trail. The accelerator may be the first.
3.5 Performance Seigniorage
Finally, the state monetizes access to yesterday’s frontier while protecting today’s. The January 2026 thresholds draw the line with numerical precision: H200 and MI325X below the line and licensable; Blackwell and Rubin above it and denied.[2,44] The result is a deliberate compute-generation gap, maintained as policy and refreshed as the frontier advances. The emerging pattern can be charted as a recurring model:
| Hardware Generation | Policy Treatment (2026) | Strategic Function |
| GB300 / Blackwell / Rubin (frontier) | Presumption of denial to China; conditional allocation to trusted partners | Protected frontier; alliance currency |
| H200 / MI325X (frontier minus one) | Case-by-case license + testing + 25% tariff mechanism + volume limits | Monetized trailing edge |
| H20 / MI308 (frontier minus two) | Licensed under the 2025 15% revenue arrangement | Mass-market managed access |
| Older hardware (A100-class and below) | Ordinary commerce or legacy controls | Background trade |
Performance seigniorage is what makes the whole system renewable rather than one-shot. Every new Nvidia generation — every Rubin, every successor — automatically re-creates the gap, re-stocks the tollbooth with a new “permitted” tier, and re-prices every license below it. The mint does not run out of coin so long as the design frontier keeps moving. Which is also, as Section 8 will argue, the system’s single point of failure: the moment the frontier stops being American, the entire structure is minting someone else’s currency.

Section 4: Corporate Incentive Reversal — Why Nvidia Tolerates the Tollbooth
A puzzle sits at the commercial heart of this story. Nvidia and AMD are being asked to surrender revenue percentages without precedent in American export history, to route their products through government-mandated testing, to accept per-customer volume caps, and to operate under a licensing regime that can be reversed by a single social-media post. Why do the companies tolerate a highly regulated export regime instead of lobbying exclusively for complete deregulation — or complete withdrawal from the Chinese market? The answer illuminates the deepest logic of Accelerator Seigniorage: controlled access may be preferable to exclusion, for the company as much as for the state.
4.1 The Scale of What Is at Stake
Begin with magnitude. Nvidia’s fiscal 2026 closed with record full-year revenue of $215.9 billion, up 65 percent; its first quarter of fiscal 2027, reported in May 2026, reached $81.6 billion in revenue — up 85 percent year over year — including $75.2 billion from the Data Center segment alone, itself up 92 percent, with guidance of roughly $91 billion for the following quarter that assumed no China datacenter compute revenue at all.[21,22,23] These are numbers without close historical analogue: a single company’s quarterly data-center line now exceeds the annual GDP of most United Nations member states. Jensen Huang’s own description of the moment doubles as the macroeconomic context for everything in this paper:[22]
“The buildout of AI factories — the largest infrastructure expansion in human history — is accelerating at extraordinary speed.”
— Jensen Huang, founder and CEO, Nvidia [22]
Against that backdrop, a 15 or 25 percent toll on one national market segment is a cost of doing business — painful, margin-diluting, legally novel, but bearable. Susannah Streeter of Hargreaves Lansdown read the August 2025 deal exactly this way at the time:[8]
“Another example of a mega tech company acquiescing to the US administration’s demands.”
— Susannah Streeter, Hargreaves Lansdown [8]
Ray Wang of Constellation Research needed only one word for the arrangement — “bizarre” — while noting the unresolved incoherence at its core: either the chips are a national-security problem or they are not, and a payment percentage answers neither branch of that question.[9] The companies pay anyway. The reason lies one level deeper than revenue.
4.2 Hardware Creates Software Dependence
An accelerator is not a commodity in the economic sense, because it is not interchangeable with its substitutes once adopted. For Nvidia, the moat is CUDA: the software platform, libraries, developer tooling, networking stack, and optimization ecosystem accreted over nearly two decades. A Chinese company purchasing Nvidia GPUs is not merely acquiring silicon; it is enrolling its engineers, its codebases, its inference pipelines, and its hardware roadmap in an American ecosystem. Every model trained on CUDA, every kernel hand-tuned for Hopper, every cluster architected around NVLink deepens a dependence that survives the individual chip’s depreciation. Hardware sales are ecosystem enrollment.
4.3 Washington’s Strategic Choice — and the Dependency Dividend
This is what transforms the corporate argument into a geopolitical one, and it is why Huang’s commercial advocacy found traction in a security debate. Washington faces a genuine strategic fork: deny American accelerators and thereby subsidize the maturation of Huawei’s Ascend and Cambricon alternatives inside a captive domestic market — or permit selected American accelerators and preserve Chinese dependence on an American technology stack that Washington can observe, meter, and interrupt. The choice is not between leverage and no leverage; it is between leverage that decays through disuse and leverage that renews through use.
Call the second path’s payoff the Dependency Dividend. Under controlled access, the exporter receives revenue; the customer receives compute; but the exporting country receives something neither party fully prices: continuing ecosystem influence — the assurance that the rival’s AI economy keeps its foundations on American terrain, where every future policy instrument, from license revocation to verification mandates, retains a purchase point. The Dependency Dividend is the strategic return that makes the tollbooth model coherent as security policy rather than mere revenue policy. It is also, candidly, a wager against time: it assumes the dependence decays slower than the substitution. Beijing’s conditional approvals — pointedly paired with domestic-purchase quotas and continued massive investment in its own stack — are best read as China wagering the opposite.[17,12] Section 8 adjudicates that bet.
For present purposes, the point is narrower: the corporate incentive reversal is real and structural. Nvidia and AMD accept the seigniorage regime because the alternative — a Chinese AI economy built end-to-end on non-American hardware and software — threatens something more valuable than a revenue percentage: the platform position itself. The state and the champion firm have arrived, from opposite directions, at the same conclusion: a tolled gate beats a sealed wall. That alignment of incentives, more than any statute, is what makes the regime stable.

Section 5: Smuggling Economics — The Gray Market as the System’s Shadow Price
Every licensing regime casts a shadow, and the shadow of Accelerator Seigniorage is the gray market in diverted chips. The critical analytical question is deceptively simple: does legal but expensive access reduce chip smuggling — or does it merely establish the price premium around which smuggling becomes profitable? The events of 2025 and 2026 supply an unusually rich evidentiary record for thinking about this, because liberalization and enforcement escalated simultaneously, which is exactly what the economics predicts.
5.1 The Black-Market Equation
The incentive structure can be captured in a simple framework, which readers should treat as an organizing identity rather than an estimable model:
Black-Market Incentive = Restricted-Chip Value − Legal Acquisition Cost − Smuggling Cost − Expected Enforcement Penalty
Each term is a policy lever. Restricted-chip value is set by the frontier gap: the more capable the denied generation relative to the permitted one, the larger the first term — which is why Blackwell, not the H200, is the smuggler’s prize in 2026. Legal acquisition cost is set by the seigniorage stack itself: tariffs, revenue shares, testing fees, queue delays, and quota scarcity all raise it. Smuggling cost is set by logistics and the tightness of transshipment jurisdictions. Expected enforcement penalty is the product of detection probability and sanction severity — and detection probability is precisely what verification seigniorage exists to raise.
The framework yields the two comparative statics that define the policy dilemma. If official supply becomes sufficiently available and reasonably priced, smuggling margins compress toward the ordinary risk premium and the gray market shrinks to opportunists. But if legal access is heavily taxed, quantitatively capped, or politically uncertain — all three of which describe the H200 channel as of mid-2026, with shipments Kessler could only call “trivial” — then gray-market arbitrage remains attractive, and the licensing regime functions less as a substitute for smuggling than as its price signal.[15] Hence the paradox that sits at the center of this section:
The government needs scarcity to produce Accelerator Seigniorage. But excessive scarcity manufactures export evasion.
Seigniorage and smuggling are not opposites; they are joint products of the same scarcity. The state’s revenue and the smuggler’s margin are both functions of the gap between world demand and licensed supply. A regulator maximizing toll revenue and a regulator minimizing diversion are pulling the same lever in opposite directions.
5.2 The Evidence of 2025–2026
Current events make this framework uncomfortably concrete. In May 2026, Commerce moved abruptly — in rare Sunday guidance — to close a loophole through which foreign subsidiaries of Chinese companies, incorporated in places like Malaysia and Singapore, had been legally acquiring the most advanced Nvidia and AMD hardware, including Blackwell- and Rubin-class processors, for nearly a year; one industry source estimated the volume in the hundreds of thousands of units.[35,36] Former State Department official Chris McGuire’s public reaction distilled the enforcement community’s alarm:[35]
“Chinese companies have been buying these chips, very likely at scale.”
— Chris McGuire, former U.S. State Department official [35]
Days later, the physical dimension surfaced in Kuala Lumpur. Malaysian customs, operating under transshipment controls tightened the previous year, raided the airport’s free trade zone on June 5 and seized 72 servers containing advanced AI chips valued at roughly $13 million, falsely declared to disguise their contents and routed through Malaysia purely as a laundering waypoint.[33,34] Airport customs director Zulkifli Muhammad’s description of the scheme is a one-sentence portrait of the modern chip gray market:[34]
“The servers were declared as ‘computer components’ to avoid detection from the authorities.”
— Zulkifli Muhammad, Director of Customs, Kuala Lumpur International Airport [34]
And beneath both episodes runs the most striking enforcement development of all: Reuters’ August 2025 revelation that U.S. authorities have secretly embedded location-tracking devices in selected high-risk shipments of AI servers — hidden in packaging and, in some cases, inside the servers themselves — as an investigative technique against suspected diversion, a tactic borrowed from aircraft-parts enforcement and now applied to the commodity at the center of the AI economy.[31,32]
5.3 From Export Administration to Compute Policing
Assemble the pieces and a new enforcement paradigm comes into view. The near future combines: legal licensing with certified customers; physical trackers in gray-zone shipments; on-chip location verification mandated by statute if the Chip Security Act or its successors pass; customs intelligence coordinated across transshipment hubs from Kuala Lumpur to Singapore; and datacenter audits verifying that licensed chips remain where their licenses say they are.[31,33,37,38] That is no longer conventional export administration — the paperwork regime of commodity codes and end-user certificates. It begins to resemble compute policing: a standing, physical, forensic apparatus for tracking a specific class of objects across the surface of the Earth, closer in spirit to nuclear-materials accounting or the tracing of high-value art than to ordinary trade compliance.
The seigniorage interpretation of this buildout is straightforward. Enforcement expenditure is the mint’s anti-counterfeiting budget. A currency is only worth issuing if forgery is kept rare; a compute-licensing regime is only worth operating if diversion is kept rare. The trackers, the seizures, the Sunday guidance, and the verification mandates are not separate stories from the tariffs and revenue shares. They are the same story: the cost side of the seigniorage ledger, paid to keep the tolled gate meaningful.

Section 6: From Chip Exports to Compute Concessions — The Emerging Global System
China is the central case of Accelerator Seigniorage, but it must not be mistaken for the whole phenomenon. The same architecture — conditional access to American accelerators, priced in a currency the granting state values — is being deployed across the map, and the non-China cases reveal that money is only one of the currencies in which seigniorage can be collected.
6.1 The Gulf Template: Access in Exchange for Security Alignment
In November 2025, the Commerce Department authorized the export of advanced semiconductors equivalent to as many as 35,000 Nvidia GB300 Blackwell chips each to G42 of the United Arab Emirates and Humain of Saudi Arabia — frontier-class hardware of precisely the generation denied to China — conditioned on rigorous security and reporting requirements, with BIS monitoring compliance on an ongoing basis.[28,29,30] The department framed the approvals explicitly as instruments of strategy rather than commerce, describing them as promoting “continued American AI dominance and global technological leadership” under the July 2025 AI Action Plan and following landmark bilateral AI partnership agreements.[28] The Emirati response confirmed that both sides understood the transaction as diplomacy denominated in compute; as the UAE’s ambassador to Washington put it:[29]
“Another milestone in the trusted and enduring partnership between our two nations.”
— Yousef Al Otaiba, UAE Minister of State and Ambassador to the United States [29]
And G42’s chief executive articulated, with remarkable candor, the reciprocal obligation embedded in the concession:[29]
“What we build in the UAE, we will continue to match in the US, maintaining symmetry and trust at every layer.”
— Peng Xiao, Chief Executive Officer, G42 [29]
Notice what is being exchanged. No 25 percent toll attaches to the Gulf allocations. The seigniorage is collected instead in security alignment: datacenter architectures auditable by American authorities, exclusion of rival vendors, reciprocal investment on U.S. soil, adoption of the American technology stack from silicon to cloud, and enmeshment of two pivotal swing states in an American-led compute order at exactly the moment China courts them. The Gulf template demonstrates the paper’s conceptual expansion:
Accelerator Seigniorage can operate through multiple currencies: money, security, investment, diplomatic alignment, datacenter location, technology-stack adoption, and intelligence cooperation.
A state operating a compute chokepoint is a monopolist that can price-discriminate not merely across customers but across currencies — charging Beijing in dollars and dependence, Abu Dhabi and Riyadh in alignment and reciprocity, and allies in adherence to common control standards. The license is the same instrument in every case; only the denomination of the toll changes.
6.2 The Emerging Global System: Accelerator Jurisdictions
Project the pattern forward and the world begins to sort into a small number of accelerator jurisdictions — tiers defined not by wealth or ideology but by the terms on which each may compute:
| Tier | Access Terms | Illustrative Cases (2026) |
| Trusted Compute States | Frontier or near-frontier chips under favorable conditions and allied control standards | Close U.S. allies and Tier-1 partners |
| Conditional Compute States | Frontier-class chips with security, reporting, ownership, and datacenter requirements | UAE (G42), Saudi Arabia (Humain) |
| Metered Compute States | Limited quantities, trailing generations, tolls, testing, and dual-sovereign approvals | China under the H20/H200 regime |
| Restricted Compute States | Presumptive denial with narrow exceptions | Entities of concern; frontier-class exports to China |
| Embargoed Compute Actors | No authorized access | Sanctioned militaries and designated end users |
The tiers are not static — the entire Chinese case demonstrates movement between them — and that mobility is itself the point. A jurisdictional ladder whose rungs are set by one sovereign converts every country’s compute ambitions into a standing negotiation with Washington. The closest historical analogue is not any prior export-control regime but the monetary architecture built at Bretton Woods: a system in which access to the scarce strategic asset — then dollars and gold convertibility, now frontier processors — was governed by rules that one state disproportionately wrote, from which that state collected an exorbitant privilege, and which every other participant accepted because the alternative to membership was exclusion from the growth of the age. This begins to resemble a Bretton Woods system for compute, except that the scarce sovereign privilege is not currency convertibility but permission to compute at the frontier.
The analogy also imports Bretton Woods’ fate as a warning. That system lasted barely a quarter century before the anchor state’s own behavior — spending its privilege faster than its credibility — forced its collapse. A compute Bretton Woods anchored on American technological indispensability will last exactly as long as the indispensability does, and not one product generation longer. That is the subject of Section 8.

Section 7: Accelerator Seigniorage and the Five-Layer AI Economy
This paper’s framework belongs inside a larger architecture: the five-layer AI economy — energy, chips, datacenters, models, and applications-and-agents — in which each layer supplies the substrate for the one above it. Accelerator Seigniorage originates in Layer Two. But a control imposed at Layer Two does not stay at Layer Two, because compute is the load-bearing input of everything stacked upon it. Tracing the propagation upward and downward is essential to grasping the phenomenon’s full economic weight.
| Layer | Domain | How Accelerator Seigniorage Propagates Into It |
| Layer One | Energy | Chip destinations determine where gigawatts of AI electricity demand appear |
| Layer Two | Chips | The direct layer: licensing, tariffs, custody, verification, generational segmentation |
| Layer Three | Datacenters | A chip license is ultimately an authorization for a physical facility to possess compute |
| Layer Four | Models | Compute access determines who can train, fine-tune, and serve frontier models |
| Layer Five | Applications & Agents | The strategic payoff: agents, robotics, discovery, defense, and economic automation |
7.1 Layer One — Energy
Where accelerators are legally allowed to operate determines where the gigawatts of AI electricity demand materialize. A hundred thousand H200s consume on the order of a small city’s power; a Gulf allocation of GB300s anchors gigawatt-class campuses like the Stargate UAE cluster; a denied license is, among everything else, a denied load-growth forecast for some national grid.[29] Control the chip’s destination and government policy indirectly draws the map of AI electricity consumption — which grids expand, which nations burn or build for intelligence, where the transformers and turbines are ordered. The August 2026 polysilicon proclamation closes the loop from the other end, extending the same Section 232 security-and-revenue logic to an input that feeds both the semiconductor and the solar-energy supply chains at once.[25,26]
7.2 Layer Two — Chips
This is the direct layer, populated by the names that recur throughout this paper: Nvidia and AMD as designers; TSMC as fabricator; SK Hynix, Samsung, and Micron as memory suppliers; Huawei, Cambricon, and CXMT as the challenger ecosystem. Everything in Sections 1 through 5 operates here. What deserves emphasis is that seigniorage instruments now reach the layer’s inputs as well as its outputs: the expiration of validated-end-user status for Samsung and SK Hynix’s China fabs, replaced by annual licenses for chipmaking-tool shipments, applies the licensing logic one step upstream, to the machines that make the memory that feeds the accelerators.[43]
7.3 Layer Three — Datacenters
A chip license ultimately authorizes a physical datacenter to possess computational capacity, and the conditions attached to 2025–2026 approvals make this explicit: security architectures at the recipient, customer screening, ownership requirements, reporting obligations, and — in the Gulf cases — ongoing BIS compliance monitoring of the facilities themselves.[2,28] Future licenses will plausibly specify location, ownership structure, and physical and cyber security design as routine terms. The datacenter is becoming a licensed premises, the way a casino or a nuclear plant is a licensed premises: a building whose contents make it an object of continuous regulatory jurisdiction.
7.4 Layer Four — Models
Compute access determines who can train, fine-tune, and serve powerful models. A country receiving 100,000 modern accelerators occupies a categorically different model-development position from one receiving 5,000 units of an older generation — not marginally different, categorically, because frontier training runs have minimum viable scales below which certain capabilities simply cannot be reached. Performance seigniorage at Layer Two therefore translates directly into a capability ceiling at Layer Four: the generational gap in silicon becomes a generational gap in intelligence. This is the mechanism by which a customs decision becomes an epistemic one — by which a tariff schedule shapes what a nation’s machines can learn.
7.5 Layer Five — Applications and Agents
The ultimate strategic value never resided in the silicon. It resides in what the silicon produces: agents, robotics, scientific discovery, military systems, autonomous infrastructure, industrial intelligence, and economic automation. Layer Five is where the returns to compute compound into national power — and it is the layer every government is actually reasoning about when it signs a chip license. The H200 debate was never about the H200. It was about what a million H200s become five years downstream.
Hence the sentence that should stand at the center of any account of this subject:
Accelerator Seigniorage is a Layer-Two policy capable of redistributing economic power across all five layers of the AI economy.
No other contemporary trade instrument has this property. A steel tariff stays in steel; an agricultural quota stays in agriculture. A compute license reaches upward into the composition of national intelligence and downward into the geography of national energy. That vertical reach is why the stakes of this policy area exceed its apparent scope — and why the counterargument of the next section matters so much.

Section 8: The Seigniorage Paradox — The Case Against the Framework’s Own Optimism
An intellectually serious version of this paper cannot be a brief for monetized export controls. It must ask whether Accelerator Seigniorage ultimately destroys the strategic advantage that makes it possible — whether the mint, by charging too much for its coin, teaches the world to mint its own. This is the strongest counterargument to everything preceding, and it deserves to be stated at full strength:
The Seigniorage Paradox: the more aggressively a country monetizes its technological chokepoint, the stronger the incentive for customers to eliminate that chokepoint.
The logic is the same wasting-asset dynamic identified in Section 1.3, now applied to the tollbooth rather than the wall. Every toll paid is also a quantified grievance — a line item in some ministry’s calculation of what technological independence would be worth. A 25 percent surcharge on the H200 is, from Beijing’s perspective, a standing subsidy announcement for Huawei: it tells every Chinese buyer exactly how much a domestic alternative may underperform and still be worth purchasing. Monetization prices the chokepoint, and pricing something is the first step toward budgeting its replacement.
8.1 The Evidence That Substitution Is Underway
China’s semiconductor policies of 2025–2026 illustrate the problem across the stack. In memory, ChangXin Memory Technologies (CXMT) — which held roughly 4 percent of global DRAM in mid-2025 — raised approximately $8.6 billion in a July 2026 Shanghai listing that briefly made it the mainland’s most valuable company, is targeting high-bandwidth memory production from the end of 2026, and is expanding wafer capacity toward the scale of the industry’s third-largest supplier.[41,42] Analysts covering the Korean incumbents now treat the question as when, not whether, the share gap narrows:[42]
“Market share ultimately comes down to production volume.”
— Lee Joo-wan, semiconductor analyst [42]
Upstream, the hedging has spread to the incumbents themselves: with validated-end-user status expiring and replaced by annual U.S. licenses for their China fabs, Samsung and SK Hynix face yearly uncertainty over American toolflows — precisely the kind of dependency risk that reporting suggests has them evaluating Chinese chipmaking equipment as insurance, even as Chinese firms progress on domestic immersion lithography.[42,43] In logic chips, Huawei’s Ascend line continues shipping at scale into the demand vacuum American policy created, and Beijing has paired every import approval with domestic-purchase expectations designed to guarantee its national champions a protected market share.[17,12] Research on the innovation effects of the controls points the same direction: restriction has accelerated Chinese interest in indigenous and open technological ecosystems rather than extinguishing it.[13]
8.2 The Self-Consuming Structure
So Accelerator Seigniorage may contain the seeds of its own destruction, and the mechanism is worth stating precisely because it is economic rather than technological. The regime’s revenue, leverage, and information all derive from a single source: the willingness of foreign buyers to pay for access to American-controlled compute. That willingness is a function of the performance gap between what America licenses and what alternatives provide, net of the toll. The toll narrows the effective gap; the gap’s narrowing raises substitution investment; substitution investment shrinks the future gap further. The system consumes its own tax base — unless the American frontier advances fast enough to re-open the gap each generation faster than the toll and the substitution close it.
That race admits no permanent winner by policy design alone. Nvidia’s roadmap — Blackwell to Rubin and beyond, with memory bandwidth targets that domestic Chinese roadmaps do not approach until years later — currently keeps the gap open.[21,44] But the gap is a fact about engineering, not about law, and every year of Chinese customs data showing record chip self-sufficiency is a year in which the sovereign privilege depreciates. Chris Miller’s mid-2026 observation that Chinese firms had still largely not converted H200 permissions into purchases — with Beijing steering demand toward Huawei’s ecosystem instead — may be the single most telling data point in this entire record: the customer at the tollbooth is not queuing to pay; it is studying the bridge to learn how one is built.[30,12]
The honest conclusion of this section is therefore conditional, and it sets up the final pillar of Section 10: seigniorage is real, collectible, and strategically potent — and it is temporary by construction. It is a franchise on indispensability. The policy debate should never be whether the toll is clever; it should be whether the toll’s proceeds and conditions are being converted into the one asset that sustains the franchise: a frontier that keeps moving away from everyone who resents paying to reach it.

Section 9: The 2026 Political Dimension — Better Questions Before November
This analysis becomes unusually relevant in the months before the November 2026 midterm elections, because chip policy has escaped the executive-branch enclave in which it was made and become a live legislative and electoral contest. The House Foreign Affairs Committee advanced the AI OVERWATCH Act — which would statutorily ban Blackwell-class exports to China and grant Congress review power over major AI chip licenses — within days of the January BIS rule; the Chip Security Act cleared the same committee unanimously in March; further measures on remote access and allied controls are moving; and Kessler’s July testimony played out before lawmakers of both parties openly furious at the administration’s handling of loopholes and licenses.[44,45,46,37,16]
Yet the public debate remains trapped in a vocabulary two generations out of date. Instead of asking candidates the simplistic question — “Are you tough or soft on China?” — the electorate and the press should be asking the questions the new regime actually poses. Ten of them follow, each traceable to a specific development documented in this paper:
1. Should national-security licenses generate government revenue at all — and if they do, what institutional firewall prevents Treasury’s interest from shaping BIS’s security determinations?[5,10]
2. Should Congress approve, or hold veto power over, major accelerator exports to adversarial states, as the AI OVERWATCH Act proposes — or does licensing belong to executive discretion?[44,46]
3. Should licensed GPUs contain mandatory location-verification mechanisms, as the Chip Security Act would require — and who bears liability when verification fails?[37,38,39]
4. Should foreign datacenters operating American frontier chips undergo inspections as a standing license condition, extending the Gulf compliance-monitoring template globally?[28]
5. Should Treasury revenue ever be permitted to enter, formally or informally, a BIS national-security determination — and how would anyone know if it did?[10,7]
6. Should states receiving American accelerators be required to adopt American cloud, networking, or cybersecurity technology — converting chip access into full-stack alignment?[28,29]
7. Should chip manufacturers bear responsibility for downstream diversion of their products — and how far down the resale chain does that responsibility run?[35,36]
8. Should remote access to foreign GPUs — renting the computation without moving the chip — be regulated equivalently to physical GPU exports, as the House’s remote-access legislation contemplates?[44,4]
9. Should America’s allies receive preferential accelerator access by right — a formalized Trusted tier — or should every jurisdiction negotiate its terms bilaterally?[28]
10. What happens when China retaliates in kind — with controls on critical minerals, memory, manufacturing equipment, or other infrastructure where Beijing holds the chokepoint — and the world discovers that seigniorage is a game two can play?[17,42]
These are not technocratic refinements. They are the constitutional, fiscal, and alliance questions of a state that has begun operating a mint whose coin is computation. Congress is already wrestling with fragments of the problem through the Chip Security Act, the AI OVERWATCH Act, and related proposals; the argument of this paper is that the fragments belong to a single institution-design problem, and that the 2026 election season is the right moment to say so out loud.[37,44]

Section 10: What Have We Learned? — Seven Pillars
Four years of policy experimentation, one unprecedented revenue arrangement, one dual-sovereign licensing regime, one enforcement apparatus in the making, and one counterargument strong enough to unmake the whole edifice: what does it all reduce to? Seven pillars, stated as propositions that the evidence of 2022–2026 supports.
Pillar One — Compute Is Becoming a Sovereign Concession
Frontier accelerators increasingly resemble strategic infrastructure whose circulation is negotiated rather than ordinary merchandise that is simply bought. The H200 that must be licensed by two governments, tested on American soil, tolled at the border, and conditioned at the destination is not a product in the classical sense; it is a concession — a grant of the right to compute, issued by the sovereign that controls the grant. Once that transformation is complete for the frontier class, it does not readily reverse, because every institution built to administer the concession — the testing labs, the revenue accounts, the verification mandates, the congressional oversight — acquires a constituency of its own.
Pillar Two — Scarcity Creates Political Rent
The technological superiority of American-designed accelerators gives Washington something governments almost never possess in international commerce: the ability to charge for access to capability itself. Not for a good, whose substitutes discipline the price; for a capability class with no adequate substitute at the frontier. That rent is collected in dollars from Beijing, in alignment from the Gulf, in adherence from allies, and in information from everyone — and its existence changes what American technology policy is for. The chokepoint has become a revenue base and a diplomatic instrument simultaneously, which no prior generation of export-control doctrine anticipated.
Pillar Three — Revenue and Security Can Conflict
A system that earns money when restricted technology is sold creates incentives that traditional export-control theory did not contemplate. The regulator simultaneously becomes gatekeeper, security authority, and economic beneficiary — three roles whose objective functions diverge exactly when the stakes are highest. The 15 percent arrangement was denounced across the spectrum as bribery-adjacent for precisely this reason, and the January architecture’s migration from negotiated revenue share to structured tariff mitigates the legal exposure without resolving the institutional one.[7,10] The republic has centuries of doctrine separating the power to tax from the power to police; it has none separating the power to license from the incentive to collect. Building that doctrine is the unfinished constitutional work of the seigniorage era.
Pillar Four — Verification May Replace Prohibition
The long-term destination of this regime is probably not universal bans, which the substitution dynamics of Section 8 render self-defeating. It is authenticated hardware, registered owners, approved locations, monitored transfers, and auditable compute — a world in which the default answer to most export questions is “yes, verifiably,” and prohibition is reserved for the unverifiable.[37,40] The Chip Security Act’s unanimous committee advance, industry’s migration from opposing verification to marketing it, and the research community’s progress on location attestation all point the same way: the wall is being replaced not by an open door but by a door that knows who walks through it.[38,39]
Pillar Five — Seigniorage Is Temporary Unless Technological Dominance Persists
A state can extract Accelerator Seigniorage only while foreign buyers still want what it controls. Once alternatives become sufficiently competitive — once CXMT’s memory, Huawei’s accelerators, and domestic Chinese tooling close enough of the gap — the privilege disappears, and no statute can retrieve it.[41,42] Therefore:
The ultimate source of Accelerator Seigniorage is not regulation. It is technological indispensability.
Every dollar of toll revenue, every diplomatic concession, every verification mandate is downstream of a single upstream fact: the American frontier is still the frontier. The moment policy begins treating the rent as the asset — rather than the R&D, the talent pipelines, the fabrication capacity, and the energy buildout that generate the rent — the system starts liquidating itself.
Pillar Six — Every Gate Summons a Counter-Gate
Dual Sovereign Licensing is not an anomaly of the China case; it is the predictable equilibrium of the system. A state that conditions exports teaches its counterparties to condition imports. Beijing’s customs bar, its selective approvals, its domestic-purchase quotas, and its steering of national champions toward Huawei constitute a mirrored seigniorage regime — collecting industrial-policy compliance where Washington collects dollars.[17,12] The endgame of universal seigniorage is a lattice of gates in which every significant chip shipment is a bilateral negotiation, and in which retaliation in other chokepoints — minerals, memory, equipment — becomes the standard grammar of technology diplomacy. Policymakers who model only their own gate are modeling half the system.
Pillar Seven — Enforcement Is Becoming Physical, and the Regime Will Be Judged There
The intellectual architecture of Accelerator Seigniorage — the taxonomies, the tariff schedules, the license conditions — is only as real as its weakest transshipment hub. Hidden trackers in server crates, seizures in Kuala Lumpur free-trade zones, Sunday-night loophole guidance, and hundreds of thousands of frontier chips reaching Chinese subsidiaries through a year-long blind spot together deliver the sobering lesson of 2026: the paper regime and the physical world diverged, badly, and the credibility of the entire seigniorage structure now depends on closing that divergence.[31,33,35,36] Compute policing is not an optional appendix to the system. It is the system’s foundation inspection — and as of this writing, the inspection is failing often enough to keep every other pillar honest.

Conclusion: The Sovereign Price of Intelligence
End where we began: with an H200 — fabricated in Taiwan, remembered in Korea, designed in California, desired in Beijing — sitting in an American testing laboratory, waiting for permission to exist commercially in the country that ordered it. Its journey home before its journey out is the whole argument of this paper compressed into an itinerary.
For decades, governments taxed the recognizable carriers of economic power: automobiles, oil, steel, cigarettes, imports, financial transactions. The objects changed; the logic did not — the state stood at a border or a ledger and collected a share of value passing through. Artificial intelligence introduces something categorically different. Governments may increasingly collect value not merely because a physical product crosses a border, but because permission to possess a particular level of computational intelligence has itself become scarce — and the scarcity is partly of the sovereign’s own manufacture, minted through thresholds, licenses, and gates the way currency is minted through a monopoly on legal tender.
That changes the meaning of an export license: from a customs formality to an economic concession, a security instrument, a revenue claim, and a diplomatic communiqué folded into one document. It changes the relationship between Nvidia and Washington: from regulated firm and regulator to something closer to concessionaire and sovereign — the champion enterprise operating the frontier under charter, remitting a share of the proceeds to the crown. It changes the relationship between Washington and Beijing: from trading rivals into dual gatekeepers of a single commodity flow, each collecting seigniorage in its own currency, each studying the other’s gate for the day it can build a better one. And eventually — if the verification infrastructure matures, if the jurisdictional tiers harden, if the polysilicon precedent propagates down the supply chain — it may change the relationship between governments and compute everywhere: toward a world in which computation is a licensed, metered, audited utility of state power, the way spectrum, currency, and airspace already are.
Whether that world is safer or merely more taxed; whether the tollbooth preserves American advantage or liquidates it; whether the Seigniorage Paradox resolves in favor of the mint or the counterfeiters — these remain open questions, and Section 8 of this paper should be read as standing testimony that the framework’s own author does not assume the optimistic answer. What is no longer open is the descriptive claim. The regime exists. Its instruments are in force. Its revenues are being collected, its trackers are in the crates, its gates are staffed on both shores of the Pacific.
And so the critical question of the next phase of the AI economy may no longer be the one the last decade asked — Who owns the chips? It may instead be the one this decade is already answering, shipment by licensed shipment:
Who possesses the sovereign authority to determine where intelligence may be computed — and what price the world must pay for permission?
Coda: Why “Accelerator Seigniorage,” Once More
The title’s defense can now be restated with the full evidence behind it. The term is earned on four grounds. First, structural analogy: like monetary seigniorage, the value here flows from a sovereign’s privileged position over a scarce instrument that others need and cannot issue for themselves — the license is the coin, the threshold is the legal-tender law, and the mint’s profit is the gap between the cost of granting permission and the price the world will pay for it. Second, multiplicity of denomination: like monetary seigniorage — which is collected as issuance profit, inflation tax, and exorbitant privilege at once — accelerator seigniorage is collected in five distinguishable forms across licensing, tariffs, custody, verification, and performance segmentation, and in currencies ranging from Treasury dollars to Gulf security alignment. Third, systemic consequence: like the currency privileges that anchored Bretton Woods, this privilege is organizing an international system around itself, sorting nations into compute jurisdictions the way the postwar order sorted them into monetary ones. Fourth, and most important, shared fragility: seigniorage of every kind survives only as long as the underlying indispensability does — debase the currency, or lose the frontier, and the privilege evaporates. A term that captures the value, the mechanism, the system, and the failure mode in a single word is doing the work a title should do. That is why this paper is called Accelerator Seigniorage.

Footnotes and Endnotes:
[1] Bureau of Industry and Security, U.S. Department of Commerce — “Department of Commerce Revises License Review Policy for Semiconductors Exported to China (January 2026).” https://www.bis.gov/press-release/department-commerce-revises-license-review-policy-semiconductors-exported-china
[2] Covington & Burling LLP — “U.S. Commerce Department Revises License Review Policy for Exports of Certain Advanced Computing Commodities to China and Macau (January 2026).” https://www.cov.com/en/news-and-insights/insights/2026/01/us-commerce-department-revises-license-review-policy-for-exports-of-certain-advanced-computing-commodities-to-china-and-macau
[3] Morgan, Lewis & Bockius LLP — “BIS Revises Export Review Policy for Advanced AI Chips Destined for China and Macau (January 16, 2026).” https://www.morganlewis.com/pubs/2026/01/bis-revises-export-review-policy-for-advanced-ai-chips-destined-for-china-and-macau
[4] Baker McKenzie — Global Sanctions and Export Controls Blog — “BIS Revises License Review Policy for Advanced Computing Commodities (AI Semiconductors) to China and Macau (January 2026).” https://sanctionsnews.bakermckenzie.com/bis-revises-license-review-policy-for-advanced-computing-commodities-ai-semiconductors-to-china-and-macau-when-exported-from-the-united-states/
[5] CBS News (Megan Cerullo et al.) — “Nvidia, AMD to Pay U.S. Government 15% of China AI Chip Sales in an Unusual Export Agreement (August 11, 2025).” https://www.cbsnews.com/news/nvidia-amd-chip-sales-china-15-percent-h20-mi308/
[6] FinancialContent MarketMinute — “U.S. Strikes Unprecedented Chip Deal: NVIDIA and AMD to Share China Revenue, Raising Margin Concerns (August 12, 2025).” https://markets.financialcontent.com/stocks/article/marketminute-2025-8-12-us-strikes-unprecedented-chip-deal-nvidia-and-amd-to-share-china-revenue-raising-margin-concerns
[7] Al Jazeera (quoting Peter Harrell, Carnegie Endowment for International Peace) — “Nvidia, AMD to Pay 15% of China Chip Sales to US Government (August 11, 2025).” https://www.aljazeera.com/economy/2025/8/11/nvidia-amd-to-pay-15-of-china-chip-sales-to-us-government-reports-say
[8] Euronews (Eleanor Butler, quoting Susannah Streeter, Hargreaves Lansdown) — “Chipmakers Nvidia and AMD to Pay 15% of China Revenue to US Government (August 11, 2025).” https://euronews.com/business/2025/08/11/chipmakers-nvidia-and-amd-to-pay-15-of-china-revenue-to-us-government
[9] CNBC (quoting Ray Wang, Constellation Research) — “Nvidia, AMD and Apple: Big Tech Is Paying Its Way Out of Trump Tariffs (August 13, 2025).” https://www.cnbc.com/2025/08/13/nvidia-amd-and-apple-big-tech-is-paying-its-way-out-of-trump-tariffs.html
[10] The Motley Fool (quoting Deborah Elms, Hinrich Foundation) — “Breakfast News: China Deal for Nvidia & AMD (August 11, 2025).” https://www.fool.com/investing/breakfast-news/2025/08/11/breakfast-news-china-deal-for-nvidia-amd
[11] Brookings Institution (quoting Jake Sullivan via The New York Times, and James Lewis, CSIS) — “If Superintelligence Isn’t Imminent, the Trump Administration May Be Right to Loosen Advanced Chip Export Controls (February 2026).” https://www.brookings.edu/articles/if-superintelligence-isnt-imminent-the-trump-administration-may-be-right-to-loosen-advanced-chip-export-controls/
[12] NPR / WUSF (quoting Chris Miller, Tufts University) — “In the Shadow of U.S. Export Controls, China Rallies Its Own Chip Industry (December 19, 2025).” https://www.wusf.org/2025-12-19/in-the-shadow-of-u-s-export-controls-china-rallies-its-own-chip-industry
[13] CommonWealth Magazine (Taiwan) — “Chris Miller’s Warning Meets Nvidia’s H200 Moment in the US–China AI Race (December 20, 2025).” https://english.cw.com.tw/article/article.action?id=4521
[14] Chris Miller (Tufts University, Fletcher School) — “The Shifting Politics of AI Chip Export Controls (December 2025).” https://chrismillersnewsletter.substack.com/p/the-shifting-politics-of-ai-chip
[15] CNBC (quoting Under Secretary Jeffrey Kessler) — “U.S. Trade Official Says ‘Very Few’ Nvidia H200 AI Chips Have Been Shipped to China (July 14, 2026).” https://www.cnbc.com/2026/07/14/nvidia-h200-ai-chips-china.html
[16] Reuters (via KFGO) — “US Official Says Nvidia Has Begun Shipping Powerful H200 AI Chips to China (July 14, 2026).” https://kfgo.com/2026/07/14/us-official-says-shipments-of-h200-chips-to-china-have-begun/
[17] Reuters (Exclusive, via Yahoo Finance) — “China Gives Nod to ByteDance, Alibaba and Tencent to Buy Nvidia’s H200 Chips — Sources (January 28, 2026).” https://finance.yahoo.com/news/exclusive-china-gives-green-light-034730976.html
[18] Forbes (Jon Markman) — “The Silicon Surrender of China to Nvidia (February 3, 2026).” https://www.forbes.com/sites/jonmarkman/2026/02/03/the-silicon-surrender-of-china-to-nvidia/
[19] Reuters (via Yahoo Finance Technology) — “U.S. Approves Chinese Companies to Buy Nvidia H200 AI Chips (May 2026).” https://finance.yahoo.com/sectors/technology/articles/u-approves-chinese-companies-buy-115220822.html
[20] Data Center Dynamics — “China Approves Nvidia H200 Purchases for ByteDance, Alibaba, and Tencent — Report (February 2026).” https://www.datacenterdynamics.com/en/news/china-approves-nvidia-h200-purchases-for-bytedance-alibaba-and-tencent-report/
[21] NVIDIA Investor Relations — “Quarterly Results and Earnings Releases, Fiscal 2026–2027.” https://investor.nvidia.com/financial-info/quarterly-earnings
[22] Quartz (via Yahoo Finance, quoting Jensen Huang) — “Nvidia Q1 FY2027 Earnings: Record Revenue, Dividend Hike (May 20, 2026).” https://finance.yahoo.com/markets/stocks/articles/nvidia-q1-fy2027-earnings-record-214649637.html
[23] TIKR Research — “NVIDIA Q1 2027 Earnings: $81.6B Revenue and Three Straight Quarters of Acceleration (May 22, 2026).” https://www.tikr.com/blog/nvidia-q1-2027-earnings-81-6b-revenue-and-three-straight-quarters-of-acceleration
[24] Sherwood News — “Nvidia Rises After Reuters Reports That China Has Approved the Sale of 400,000 H200 Chips to Chinese Tech Firms (January 28, 2026).” https://sherwood.news/markets/nvidia-rises-reports-china-approved-sale-400000-h200-chips-bytedance-alibaba-tencent-chinese-tech-firms/
[25] Wiley Rein LLP — “Trump Administration Imposes Section 232 Tariffs and Minimum Import Prices on Polysilicon and Its Derivatives (August 2026).” https://www.wiley.law/alert-Trump-Administration-Imposes-Section-232-Tariffs-and-Minimum-Import-Prices-on-Polysilicon-and-its-Derivatives
[26] GHY International — “U.S. Imposes 15% Section 232 Tariff on Polysilicon and Its Derivatives Effective December 4, 2026 (August 7, 2026).” https://www.ghy.com/trade-compliance/us-section-232-polysilicon-tariff/
[27] Norton Rose Fulbright — “US Imposes Tariffs and Minimum Import Prices on Polysilicon and Derivative Solar Products (August 7, 2026).” https://www.nortonrosefulbright.com/en/knowledge/publications/7d640477/us-imposes-tariffs-and-minimum-import-prices-on-polysilicon-and-derivative-solar-products
[28] U.S. Department of Commerce — “Statement on UAE and Saudi Chip Exports (November 19, 2025).” https://www.commerce.gov/news/press-releases/2025/11/statement-uae-and-saudi-chip-exports
[29] The National (UAE, quoting Yousef Al Otaiba and Peng Xiao) — “US Approves Export of Nvidia AI Chips to UAE and Saudi Arabia (November 20, 2025).” https://www.thenationalnews.com/future/technology/2025/11/20/uae-ai-nvidia-chips-us/
[30] Benzinga (via Yahoo Finance, on Chris Miller) — “‘Chip War’ Author Chris Miller Says China Has Been ‘Underspending’ on AI for Four Years (June 11, 2026).” https://finance.yahoo.com/sectors/technology/articles/chip-war-author-chris-miller-143104923.html
[31] Reuters (Fanny Potkin, Karen Freifeld, Jun Yuan Yong; via Yahoo Tech) — “Exclusive: US Embeds Trackers in AI Chip Shipments to Catch Diversions to China, Sources Say (August 13, 2025).” https://tech.yahoo.com/ai/articles/exclusive-us-embeds-trackers-ai-081416696.html
[32] Tom’s Hardware — “Nvidia: ‘We Don’t Install Secret Tracking Devices in Our Products’ (August 14, 2025).” https://www.tomshardware.com/tech-industry/artificial-intelligence/u-s-authorities-allegedly-placed-secret-tracking-devices-in-ai-chip-shipments-to-china-report-claims-targeted-shipments-from-dell-and-super-micro-containing-nvidia-and-amd-chips-had-trackers-in-packaging-and-servers-themselves
[33] Agence France-Presse (via Khaleej Times) — “Malaysian Customs Foil $13-Million AI Chip Smuggling Bid (June 26, 2026).” https://www.khaleejtimes.com/world/asia/malaysian-customs-foil-13-million-ai-chip-smuggling
[34] AFP / World News (quoting Zulkifli Muhammad, Kuala Lumpur airport customs director) — “Malaysian Customs Foil $13-Million AI Chip Smuggling Bid (June 26, 2026).” https://article.wn.com/view/2026/06/26/Malaysian_customs_foil_13million_AI_chip_smuggling_bid/
[35] CNBC / Reuters (quoting Chris McGuire) — “U.S. Takes Step to Halt Nvidia AI Chip Shipments to Chinese Firms Outside China (May 31, 2026).” https://www.cnbc.com/2026/05/31/us-takes-step-to-halt-nvidia-ai-chip-shipments-to-chinese-firms-outside-china.html
[36] Tom’s Hardware — “US Closes Loophole That Allowed Chinese-Owned Subsidiaries Located Outside China to Buy AI Chips (June 1, 2026).” https://www.tomshardware.com/tech-industry/us-closes-loophole-that-allowed-chinese-owned-subsidiaries-located-outside-china-to-buy-ai-chips-report-claims-that-hundreds-of-thousands-of-advanced-ai-chips-have-been-acquired-through-bis-blind-spot
[37] U.S. Congress, 119th Congress — “H.R. 3447 — Chip Security Act (Text as Introduced, May 15, 2025).” https://www.congress.gov/bill/119th-congress/house-bill/3447/text
[38] Startup Fortune — “Congress Wants to Put a GPS Tracker on Every Nvidia Chip That Leaves the Country (June 19, 2026).” https://startupfortune.com/congress-wants-to-put-a-gps-tracker-on-every-nvidia-chip-that-leaves-the-country/
[39] NBC News — “Bill That Would Mandate AI Chip Location Tracking Gains Industry Support (June 18, 2026).” https://www.nbcnews.com/tech/tech-news/chips-security-act-gains-industry-support-letter-rcna350500
[40] arXiv (multi-author research consortium, building on Sastry et al. 2024) — “Hardware-Enabled Mechanisms for Verifying Responsible AI Development (2025).” https://arxiv.org/pdf/2505.03742
[41] CNBC — “CXMT’s Blockbuster Debut in Shanghai Sets Stage for Next Test Against Global Memory Giants (July 31, 2026).” https://www.cnbc.com/2026/07/31/cxmts-sk-hynix-samsung-micron-memory-chip.html
[42] Korea JoongAng Daily (quoting analyst Lee Joo-wan) — “Samsung and SK Hynix Face Rising China Chip Threat as CXMT Expands DRAM Capacity (August 1, 2026).” https://www.koreajoongangdaily.com/business/after-stock-market-whiplash-koreas-chip-industry-now-faces-growing-china-risknbsp/12801305
[43] Reuters (Hyunjoo Jin, via CNBC) — “U.S. Approves Samsung, SK Hynix Chipmaking Tool Shipments to China for 2026 (December 30, 2025).” https://www.cnbc.com/2025/12/30/us-approves-samsung-sk-hynix-chipmaking-tool-shipments-to-china-for-2026-reuters.html
[44] Introl Research Blog — “BIS H200 Export Policy China: Case-by-Case Review Controversy 2026 (February 2026).” https://introl.com/blog/bis-h200-export-policy-china-case-by-case-controversy-2026
[45] Foundation for Defense of Democracies — “Even Limited Sales of High-End Chips to Chinese Buyers Pose a Serious Risk (July 16, 2026).” https://www.fdd.org/analysis/2026/07/16/even-limited-sales-of-high-end-chips-to-chinese-buyers-pose-a-serious-risk/
[46] Forkast (Priya Nair) — “US Approves H200 Chip Sales to Chinese Firms as Senate Advances Bill to Block Them (July 15, 2026).” https://forkast.news/us-approves-h200-chip-sales-to-chinese-firms-as-senate-advances-bill-to-block-them/
[47] Reuel, A., et al. (arXiv) — “Open Problems in Technical AI Governance (2024).” https://arxiv.org/pdf/2407.14981
[48] Institute for AI Policy and Strategy (Brass & Aarne and related work) — “Compute Governance Research: Location Verification for AI Chips.” https://www.iaps.ai/research/tag/Compute+governance



