Concept

Compute Export Controls

Compute Export Controls

Compute export controls are the United States’ attempt to slow China’s artificial intelligence by cutting it off from the most advanced computer chips and the machines that make them. The bet, placed by the Biden administration in October 2022 — a month before ChatGPT — is that AI capability tracks compute: the more computing power you pour into a model, the better it gets. If that is true, then whoever controls the chips controls the frontier. The controls try to make the chips a choke point China cannot get past.

The analogy a lawyer might reach for is a restrictive covenant that runs with a supply chain rather than with land: the US does not merely refuse to sell its own chips to China, it asserts the right to block any chip anywhere in the world that was made using US technology — and because US tools are woven through every step of advanced chipmaking, almost every cutting-edge chip is caught.

The choke-point logic

The advanced-chip supply chain is narrow and allied. Chips are designed largely by NVIDIA (US), fabricated by TSMC (Taiwan), and etched by lithography machines from ASML (Netherlands), with a handful of tool-makers — Applied Materials, KLA, Lam Research (US), Tokyo Electron (Japan) — supplying the rest. China sits outside this chain. The regulatory lever is the foreign direct product rule, the ‘US-tech hook’: because it is effectively impossible to design US technology out of the process, Washington can claim jurisdiction over chips built anywhere. The technique was first used against Huawei in 2020 and then widened from a single company to a whole class of chips bound for a whole country.

The controls were designed to ‘boil the frog’. They did not need to strangle Chinese AI overnight; the theory was that as frontier training runs demand exponentially more compute, the penalty for being denied the best chips compounds — a six-month lag today becomes an unbridgeable one later.

The loopholes

Four years on, the enforcement gaps are visible. Chips are smuggled. Only a handful of US officials police what actually crosses into China. And the largest hole is not hardware at all: nothing stops a Chinese company from renting an American cloud and training its model on US soil under a front account — DeepSeek could train its next model entirely on Microsoft, Amazon, or Google cloud without breaking any law. Defenders answer that compute sitting on a US cloud is still better than compute inside China, because in principle it can be switched off; sceptics reply that you cannot press a button you cannot aim.

Distillation, the fast-follower’s counter

The controls also assumed a simpler race than the one that arrived. Distillation lets a follower query a leading model and harvest its outputs as training data — reverse-engineering much of a frontier capability for a fraction of the cost, without hiring the PhDs who generated the original data. So even as the leader’s models improve exponentially through recursive self-improvement, the follower’s ability to copy them improves too. China stays close not by matching the compute but by copying the output — which is why the ‘intelligence explosion’ that was supposed to end the race by letting one side go vertical looks, in practice, far messier: real-world AI must still be deployed into cautious institutions, one workflow at a time.

Where mainstream views differ

The policy’s own architects and its most sympathetic critics part company on whether it was the right bet.

The architect’s defence (Chris McGuire, who ran the China-tech file on the Biden NSC): the North Star is simply to keep the largest possible US lead, and almost nothing argues against that. The controls are biting — Huawei can stack chips in a data centre but produces perhaps 4% of NVIDIA’s AI compute, with a quality gap widening from roughly 5× to 17× on its own roadmap — and even shifting global compute onto US soil is a win in itself. Jointly managing the technology with an adversary who views arms control as a Cold War trap would be, in his phrase, ‘profoundly more risky’.

The sceptic’s critique (Sebastian Mallaby, a 2022 supporter now second-guessing): making China the enemy foreclosed the alternative of recruiting it into a non-proliferation alliance against the threat that should worry us more — powerful open-weight models, downloadable and un-recallable, that a rogue actor could turn to a bioweapon or an un-switchable cyberattack. On this reading the real analogy is the Nuclear Non-Proliferation Treaty: supply AI to all who want it, on condition they do not release it open-source and dangerous. It is a bargain only the two AI superpowers together can impose — and the chip war may have made it impossible.

See also