Hello, this is Ryuta Hamamoto from TIMEWELL.
"What is the Chip Security Act?" "Will Nvidia chips get GPS?" "Does this affect Japanese companies?" Export-control teams keep asking me these questions.
The Chip Security Act (S.1705 / H.R.3447), under consideration in the U.S. Congress, would require advanced AI chips exported from the United States (Nvidia H100/H200/B200 and similar) to include a location-verification mechanism. The House Foreign Affairs Committee advanced the bill 42–0 in March 2026. Bipartisan support is real.
That said, as of May 2026 the bill has not become law. The Senate version remains referred to the Banking Committee awaiting action. For Japanese companies, the practical priority is less "when will it pass?" and more "what would change if it did?"
Below I walk through the terminology, the bill's structure, industry reactions, impact on Japanese companies, and five preparation steps, written so first-time export-control owners can follow along.
What you will learn
- The formal content of the Chip Security Act (S.1705 / H.R.3447) and its legislative status (not enacted as of May 2026)
- The difference between “location verification” and a “kill switch” (remote disablement)
- Why industry mainstream voices (Nvidia, SIA, ITI) oppose the bill while Atlantic Council, CAIS, and others support it
- Enforcement cases and allegations cited as background for the bill, including third-country diversion concerns around advanced GPUs and export-control conspiracy indictments
- Additional compliance that AI infrastructure operators and resellers in Japan would face if the bill becomes law
- Five practical steps to take now
- How to get ahead of export-control work with the TRAFEED AI agent without waiting for enactment
Three terms to understand first
Before the bill text, lock in three terms. In plain language, this is about confirming that leading U.S.-made AI chips are physically where exporters say they are.
Chip Security Act
A bill under consideration in the U.S. Congress (literally, a "chip security" statute). The Senate version is S.1705; the House version is H.R.3447; the substance is essentially the same. The core idea is to require location-verification mechanisms on advanced AI semiconductors (including Nvidia GPUs) and to create reporting duties to the Commerce Department if a chip moves to an unexpected location after export.
Location verification mechanism
An umbrella term for technologies that confirm a chip's physical location.
- GPS approach: put a GPS receiver on the chip (higher cost; weaker indoors)
- Ping / latency approach: estimate location from round-trip delay to known servers (no GPS; lower cost)
- Landmark-server approach: multilateration using multiple reference servers
The bill is technology-neutral. It does not prescribe a method; manufacturers may choose.
ECCN 3A090 / 4A090
These are classification numbers under the U.S. Export Administration Regulations (EAR). ECCN (Export Control Classification Number) is the category label used to administer export controls.
- 3A090: advanced AI semiconductors (Nvidia H100/H200/B200, AMD MI300, and similar)
- 4A090: computers and servers that incorporate 3A090 chips
- 3A001.z / 4A003.z: related integrated circuits and related computer products
The Chip Security Act's scope covers these four ECCNs (and any future successor classifications).
When you start seeing ECCN, EAR, and BIS in the same paragraph, you are in export-control territory. The next section unpacks what the bill would actually require.
Structure of the bill — what would be mandated
The Chip Security Act would create three main sets of duties.
Duty 1: Embed location verification (manufacturers)
| Item | Content |
|---|---|
| Scope | ECCN 3A090 / 4A090 / 3A001.z / 4A003.z |
| Obligated parties | Chip manufacturers (Nvidia, AMD, and others) |
| Deadline | Within 180 days after the law takes effect |
| Technical method | Software, firmware, or hardware; no method prescribed |
Manufacturers would have to embed a mechanism that can confirm where a covered chip is physically located. Technical commentary has noted that current Nvidia products already include network-communications hardware, so adding location verification via firmware updates may be technically feasible. Nvidia itself, however, opposes the bill.
Duty 2: Reporting (exporters)
Exporters would have to report to the U.S. Bureau of Industry and Security (BIS) if they become aware of either:
- Diversion: the chip was redirected away from the declared end destination
- Tampering: the location-verification mechanism was altered
BIS is the U.S. agency that administers dual-use export controls, roughly analogous to Japan's METI trade-control functions.
Duty 3: Research program (government)
The bill also directs the Commerce and Defense Departments to research future chip-security mechanisms. Location verification is framed as a first step; additional capabilities could be layered on later.
The bill does not require a "kill switch"
This distinction matters more than most headlines admit.
- The bill would mandate location verification
- Remote disablement (a kill switch) is not a statutory requirement
Industry and Chinese stakeholders have still raised concerns that location tracking could later expand into kill-switch functionality. Nvidia's Chief Security Officer, David Reber, has opposed non-consensual remote disablement as "a gift to hackers," warning against repeating the 1990s Clipper Chip failure.
| Function | Treatment in the bill | Status |
|---|---|---|
| Location verification | Mandated | Core of the bill |
| Tamper detection and reporting | Mandated | Core of the bill |
| Remote disablement (kill switch) | Not required | Industry concern |
| Monitoring of usage content | Not included | Separate issue |
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Where the debate stands
The following reflects the legislative picture as of May 2026. Treat any "likely passage" claims as forecasts only.
Congressional status
| Chamber | Progress |
|---|---|
| House (H.R.3447) | Advanced 42–0 by the Foreign Affairs Committee on March 26, 2026; awaiting floor vote |
| Senate (S.1705) | Introduced May 8, 2025; referred to Banking, Housing, and Urban Affairs; markup date not set |
| FY2026 NDAA | Enacted December 18, 2025 without this bill |
| FY2027 NDAA | Packaging into the next NDAA remains possible but unconfirmed |
Co-sponsors — a bipartisan cast
| Chamber | Member | Party / note |
|---|---|---|
| Senate | Tom Cotton | Republican (Arkansas) / sponsor |
| Senate | Elizabeth Warren | Democrat / Banking ranking member; joined as co-sponsor in early 2026 |
| Senate | Maggie Hassan | Democrat |
| House | Bill Huizenga | Republican / sponsor |
| House | Bill Foster | Democrat / sponsor |
| House | John Moolenaar | Republican / Chair, House Select Committee on China |
| House | Raja Krishnamoorthi | Democrat |
Cotton and Warren rarely share a bill. Stopping AI-chip diversion has become one of the few bipartisan common denominators in Congress.
Why committee passage made news
The March 2026 House Foreign Affairs vote came shortly after federal prosecutors in the Southern District of New York charged three individuals, including a senior vice president at a major server manufacturer, with conspiracy to violate export controls. Those charges are against individuals and do not establish corporate guilt. Still, such enforcement actions have been cited as political background for advancing the bill.
Industry reaction — semiconductor majors oppose
Despite bipartisan political support, the industry mainstream is opposed. That still surprises first-time readers.
Opponents
| Actor | Stance | Main argument |
|---|---|---|
| Nvidia (CSO David Reber) | Strongly opposed | "A kill switch is a gift to hackers. Don't repeat Clipper Chip." |
| SIA (CEO John Neuffer) | Opposed | Opposes blanket mandates for unproven on-chip mechanisms; rushed legislation would damage global trust in U.S. semiconductors |
| ITI | Opposed | Warns of "unintended consequences" |
| Center for Cybersecurity Policy | Opposed | Location features themselves could create new cyber vulnerabilities for U.S. systems and dependent allies |
| NYU JIPEL ("Chip Wall" paper) | Cautious | Topology-based methods are easy to spoof; latency-based methods are imprecise |
Supporters
| Actor | Stance | Main argument |
|---|---|---|
| CAIS Action Fund | Pro | Technically feasible today; low-cost ping methods need no GPS |
| Atlantic Council | Supportive | Could enable a "trusted trade" era of expanded exports to trusted allies |
| Foundation for American Innovation (FAI) | Supportive | After-the-fact audits cannot stop smuggling |
How to read the split
Opponents essentially say: do not mandate unfinished technology across the board. Supporters say: post-hoc audits cannot keep up, so detection must live on the chip. AI-safety communities are leading the pro-bill case.
The Atlantic Council's trusted trade framing matters for Japan. If location verification can prove chips sit in trusted places, ally-bound exports could be liberalized rather than restricted. Whether Japan is treated as "trusted" is a substantive policy question, not a footnote.
Background — why now
The bill did not appear from nowhere. It follows a series of AI-chip diversion concerns involving China as a destination market. The episodes below are stated as reported facts, charges, or allegations. Listing or enforcement against an individual is not the same as a finding of corporate guilt.
Four episodes cited as catalysts
| Episode | Period | Content |
|---|---|---|
| Advanced GPU procurement concerns | Early 2025 | A House Select Committee on China report raised questions about whether certain Chinese AI developers used Nvidia H100–class chips that may have entered via third countries. These remain allegations/concerns, not adjudicated findings of corporate violations |
| Singapore fraud charges | February 2025 | Singapore authorities charged three people with fraud involving false end-destination declarations for Nvidia chips |
| FT investigative reporting | 2025 | Reporting that roughly $1 billion in Nvidia chips may have flowed to China via Southeast Asia over three months; Singapore's share of Nvidia sales reportedly jumped from 9% to 22% |
| Server-manufacturer officer indictments | March 2026 | SDNY charged three individuals, including a senior VP at a major server maker, with export-control conspiracy. Charges are individual; they do not establish corporate guilt. Such enforcement has been cited as legislative background |
The Select Committee report in particular sharpened congressional concern that even with advanced export controls in place, restricted chips may still move through third countries. That concern remains at the allegation stage, but the Chip Security Act is positioned as a technical answer to a "rules exist, verification is hard" problem.
Relationship to existing rules
The Chip Security Act would not replace the EAR. It would add a technical detection layer on top of existing frameworks.
| Rule | Overview |
|---|---|
| EAR | Dual-use export controls administered by BIS |
| Entity List | Organizations requiring licenses or facing denials (a regulatory designation, not a moral judgment) |
| FDPR | Extends U.S. controls to foreign products made with U.S. technology |
| Affiliates Rule (50% rule) | Issued September 2025; extends Entity List controls to majority-owned subsidiaries |
| AI Diffusion Rule / Advanced Computing IFR | 2023–2025 advanced AI chip controls |
If enacted, institutional “nets” and on-chip detection would operate together.
Impact on Japanese companies (if enacted)
Treat the following as a scenario if the bill becomes law. As of May 2026 it is not law.
Companies most directly affected
| Category | Additional work likely |
|---|---|
| AI infrastructure operators (own data centers) | Operations that assume chips remain at BIS-registered locations; procedures for physical relocation |
| Cloud providers (AWS Tokyo, Azure Japan East, GCP Tokyo, etc.) | Limited impact on region operations, but more process around hardware refresh and relocation |
| Resellers / trading companies | Stricter EAR re-export reviews when Japanese buyers re-export Nvidia chips; possible location-data matching |
| Equipment makers embedding AI semiconductors | Product lifecycles that absorb firmware update cycles for location features |
Likely new compliance tasks
- Internal records of chip serial numbers and physical locations (asset-register expansion)
- Location updates and stakeholder notices on moves or disposal
- Notification routes to BIS (typically via suppliers) if loss, tampering, or unexpected relocation is discovered
- Location data in re-export license applications
- Contract clauses with suppliers and distributors covering location-tracking obligations
Not only downside for Japan
Often missed in commentary: the Chip Security Act is debated together with a trusted trade idea that would ease, not tighten, exports to trusted allies.
- Rapidus (2 nm production plans)
- SoftBank Stargate Japan and other large AI infrastructure investments
- Domestic cloud providers expanding GPU capacity
For these efforts, inclusion in a "trusted" frame could make large-scale U.S. chip procurement easier. That direction is consistent with METI's December 2025 "Future Direction of the Semiconductor and Digital Industry Strategy."
Dual compliance with the U.S. EAR and Japan's Foreign Exchange and Foreign Trade Act will still grow heavier.
Non-passage is also a real scenario
As of May 2026, the Chip Security Act has not been enacted. Non-passage remains entirely plausible.
| Non-passage scenario | Content |
|---|---|
| Industry lobbying | Strong SIA / ITI / Nvidia opposition could force major floor amendments |
| Senate bottleneck | Banking Committee bandwidth consumed by crypto legislation (Digital Asset Market Clarity Act); markup date unset |
| Executive priorities | Other economic-security bills may crowd the calendar after the presidential cycle |
| Technical feasibility debate | NYU JIPEL-style critiques that location tech does not scale may not resolve within the session |
Over-preparing as if passage is certain is a risk. Doing nothing because passage seems unlikely is also a risk. The practical answer is minimum preparation for a passage scenario.
Five practical preparation steps
These steps retain value even if the Chip Security Act never becomes law — they support current EAR work on the Affiliates Rule and AI Diffusion Rule.
Step 1: Inventory U.S.-origin AI chips in use
List where U.S.-origin AI chips sit and how many you have.
- GPU models, serial numbers, and locations in company data centers
- Chips at overseas subsidiaries and sites
- Lab / development / test environments
- Chips scheduled for disposal or sale
Without this baseline, nothing else works.
Step 2: Review supplier contracts
Check export-control language with Nvidia, Dell, HPE, SuperMicro, and similar suppliers.
- Re-export restriction clauses
- End-user notification duties
- Location-data handling clauses (may be added later)
Step 3: Build re-export license workflows
If group companies may move U.S.-origin chips to third-country sites (especially non–Group A destinations), document EAR re-export application flows.
- Internal approval starting points
- Application path to BIS (via U.S. subsidiary or direct)
- Lead-time assumptions from filing to approval
Step 4: ECCN classification process
Create an internal process to classify new hardware and software against ECCN 3A090 / 4A090 and related controls.
- Owning team and responsible officers
- Retention of classification rationales
- Double-check controls against misclassification
Step 5: Automate export control with an AI agent
Running steps 1–4 by hand forever is not realistic. Product-by-product and deal-by-deal ECCN classification, Entity List screening, and Affiliates Rule (50%) ownership chains need dedicated headcount if done manually.
TIMEWELL's TRAFEED (formerly ZEROCK ExCHECK) is an AI agent purpose-built for export control.
- Automated ECCN classification (aligned with METI standards)
- Automated Entity List matching
- Parent–subsidiary tracking for the Affiliates Rule (50% rule)
- Multilingual matching (including Chinese and English entity names)
If the Chip Security Act becomes law, location matching will be added on top. The foundation work of which chips, which ECCNs, which end users is still worth automating now.
Common misconceptions / FAQ
Misconception 1: “It already became law”
Fact: Not enacted as of May 2026. House floor vote pending; Senate committee action pending.
Misconception 2: “User activity will be monitored”
Fact: The bill targets physical location of chips, not usage content or personal data.
Misconception 3: “Kill switches will be mandatory”
Fact: The bill text does not require remote disablement. Industry and Chinese stakeholders still worry about future expansion.
Misconception 4: “Japanese companies are already in violation if they don’t comply”
Fact: No Chip Security Act obligations exist until enactment. Existing EAR duties (Affiliates Rule, AI Diffusion Rule) still apply separately.
Misconception 5: “Japanese companies only lose on procurement”
Fact: Paired with trusted-trade ideas, Japanese inclusion could stabilize or improve access.
Latest developments as of July 2026
The Chip Security Act itself remains unenacted as of July 2026, but the broader “trusted trade” architecture among allies continues to take shape. The 16th Japan–India Annual Summit on July 2, 2026 produced a joint declaration on economic-security cooperation across semiconductors, critical minerals, clean energy, ICT (subsea cables), and pharmaceuticals, with roughly ¥2 trillion in investment framed (Japan–India joint press conference (Prime Minister’s Office, July 1, 2026)). Completing semiconductor supply chains among allies and partners overlaps this article’s question of whether Japan sits inside the U.S. “trusted” frame. For Japanese companies, inventorying chips and building ECCN processes before those frameworks solidify has growing practical value. Related developments are covered in Japan–India Summit 2026 and economic security.
If you want to improve export-control operations or classification efficiency, review the TRAFEED service catalog (PDF) or contact us.
Key takeaways
If you only do one thing this week, inventory U.S.-origin AI chips already on your floor. The rest of the map:
- The Chip Security Act (S.1705 / H.R.3447) is a bipartisan bill that would require location verification on advanced U.S. AI chips. Not enacted as of May 2026
- House Foreign Affairs advanced it 42–0; Senate committee action is pending
- The bill mandates location verification only; kill switches are not required
- Industry mainstream (Nvidia, SIA, ITI) opposes; CAIS, Atlantic Council, and others support
- Background includes reported third-country GPU diversion concerns and export-control enforcement cases
- For Japan, inclusion in a trusted trade frame is the key variable; procurement could ease
- Do not wait for enactment: chip inventory, contract review, re-export workflows, and ECCN processes should start now
- TRAFEED can automate much of that export-control workload
My view: the smartest posture is not "unrelated because unenacted," but "prepare the minimum for a passage scenario starting now."
Related articles
- MATCH Act and Japan–U.S. semiconductor export controls
- Complete guide to the BIS Affiliates Rule (50% rule)
- China export risk 2026
- AI export regulation 2026
- Export-control violation penalties and risk
Before the Chip Security Act — strengthen the export-control foundation you already need
Whether or not the Chip Security Act becomes law, Affiliates Rule (50%) screening, AI Diffusion Rule compliance, and Entity List matching already demand serious capacity. TRAFEED, TIMEWELL's export-control AI agent, automates ECCN classification through ownership-chain tracking end to end.
References
Congressional and government sources
- H.R.3447 - 119th Congress (2025-2026): Chip Security Act
- S.1705 - 119th Congress (2025-2026): Chip Security Act
- H.R.3447 GovInfo (official IH PDF)
- Senator Cotton press release
- House Foreign Affairs Committee press release (HFAC passage)
- House Select Committee on China press release
Industry and think tanks
- SIA statement
- ITI commentary
- Atlantic Council analysis (trusted trade)
- Center for Cybersecurity Policy (opposition)
- NYU JIPEL (Chip Wall paper)
- CAIS Action Fund (support)
- Foundation for American Innovation
Related cases
- Tom's Hardware: DeepSeek smuggled Nvidia GPUs via Singapore
- Fortune: Singapore charges three with fraud
- Yahoo Finance: Chip Security Bill Advances After Super Micro Case
Press
- The Hill: Cotton unveils legislation
- The Register: GPU tracking bill gains bipartisan support
- Washington Trade & Tariff Letter: Warren joins Cotton bill
- CNBC: Nvidia denies kill switch claims





