TRAFEED

Operation Gatekeeper Explained | Five Practical Risks from a $160M AI-Chip Diversion Case

Published2026-05-20Updated2026-07-06Ryuta Hamamoto

In December 2025, DOJ and BIS announced Operation Gatekeeper, an alleged network that tried to divert about $160 million of NVIDIA H100/H200 GPUs to China.

Operation Gatekeeper Explained | Five Practical Risks from a $160M AI-Chip Diversion Case
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

“We’re not a U.S. company. This doesn’t apply to us.” I still hear that when export controls come up at mid-sized firms. Operation Gatekeeper, announced by the U.S. Department of Justice (DOJ) in December 2025, is a reminder that that assumption can be the most dangerous one.

U.S. authorities described a network centered on a Texas company that allegedly tried to move about $160 million worth of NVIDIA H100/H200 GPUs toward China. The method was simple on paper: strip NVIDIA barcodes, apply fake “SANDKYAN” labels, and route shipments through Singapore to Hong Kong, with documents calling the goods “adapters” or “general computer parts.”

This is not a distant U.S. story only. Japanese trading companies, electronics distributors, and semiconductor equipment makers can be drawn into similar patterns. Below I map the public facts of the case and five practical steps you can start this week.

Where individuals remain at the indictment stage and plead not guilty, this article treats allegations as allegations. One defendant has pleaded guilty; others have not been convicted. The facts below are regulatory and judicial outcomes, not character judgments of every party named in public materials.

What you will learn

  • What Operation Gatekeeper is, and why it is called the first AI-diversion guilty plea of its kind
  • The six-stage diversion path (straw purchase → warehouse aggregation → label fraud → third-country routing)
  • The statutes at issue (ECRA / EAR Part 744 / FDPR) and penalties up to 20 years and $1 million
  • Five red flags Japanese companies should check
  • Five steps to strengthen controls this week

Three acronyms first (DOJ / BIS / ECRA)

Acronym Full name Role
DOJ Department of Justice Criminal prosecution; oversees U.S. Attorneys’ offices and FBI
BIS Bureau of Industry and Security Administers the EAR; licensing and Entity List management
ECRA Export Control Reform Act of 2018 Statutory basis for criminal and civil export-control penalties (up to 20 years + $1M)

In short: BIS writes and administers the rules; DOJ prosecutes; ECRA supplies the penalty framework. Gatekeeper followed that pattern. Keep the three roles separate when you brief management.

Case overview: 9 December 2025, ~$160M attempted diversion

Item Detail
Operation name Operation Gatekeeper
Public announcement 9 December 2025
Agencies DOJ, BIS, FBI, HSI, U.S. Attorney’s Office for the Southern District of Texas
Seizures reported About $50 million (GPUs and cash)
Attempted diversion value About $160 million
Period October 2024 – May 2025 (~7 months)
Items NVIDIA H100 / H200 Tensor Core GPUs
Suspected ultimate destinations PRC and Hong Kong

H100/H200 are top-tier NVIDIA GPUs for generative AI training and inference, often priced in the tens of thousands of dollars each. Moving roughly $160 million over seven months (about ¥24 billion) is large enough that questions about state-level interest are not surprising from an enforcement perspective. That is an enforcement lens, not a claim I am making about any end customer’s intent.

Southern District of Texas U.S. Attorney Nicholas J. Ganjei stated that the network sought to transport cutting-edge AI technology to those acting against U.S. interests and presented a direct national-security threat. I quote that as the prosecutor’s framing of the case.

The case was run through the Disruptive Technology Strike Force, a joint DOJ–BIS initiative launched in February 2023 and deployed across 12 metro areas to focus on advanced-technology diversion.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Named defendants: including the first AI-diversion guilty plea

Alan Hao Hsu (43): guilty plea entered

  • Residence: Missouri City, Texas
  • Company: Hao Global LLC (Houston area)
  • Plea: 10 October 2025, guilty to smuggling and illegal export charges
  • Sentencing scheduled: 18 February 2026; statutory exposure up to 10 years
  • Wire transfers from the PRC: over $50 million

DOJ materials highlight this as the first guilty plea in an AI diversion case: the first time a principal has admitted guilt in an AI semiconductor diversion prosecution of this kind.

Benlin Yuan (58, Canadian citizen): indicted; not guilty plea

CEO of an IT services firm in Sterling, Virginia, and operator of a U.S. subsidiary of a Beijing-based company. Arrested 28 November 2025. Charged with conspiracy to violate ECRA (up to 20 years + $1M). The indictment alleges recruiting and organizing people in the U.S. to inspect mislabeled GPUs for a Hong Kong logistics firm. He has pleaded not guilty.

Fanyue “Tom” Gong (43, Chinese citizen): indicted; not guilty plea

Owner of a Brooklyn, New York technology company. Arrested in New York City on 3 December 2025. Charged with conspiracy to smuggle goods from the United States (18 U.S.C. § 554; up to 10 years). The indictment describes directing warehouse work to strip NVIDIA logos/barcodes and apply “SANDKYAN” labels. He has also pleaded not guilty.

Yuan and Gong await jury trial in Houston federal court. Only Hsu has pleaded guilty among the three publicly named individuals. Treat the open cases as open cases.

Six-stage path: how U.S. GPUs were allegedly moved

[1] Straw purchase  →  [2] U.S. warehouse aggregation  →  [3] Label fraud  →
[4] Shipping document fraud  →  [5] Third-country routing  →  [6] PRC / Hong Kong arrival
Stage Alleged method
1. Straw purchase Buy GPUs via straw purchasers; invoices claim domestic or license-free third-country customers
2. Warehouse aggregation Aggregate GPUs in Texas, North Carolina, and other warehouses
3. Label fraud Remove NVIDIA barcodes/logos; apply fake “SANDKYAN” labels
4. Document fraud Misclassify as “general computer parts” or “adapters”
5. Third-country routing North Carolina → New York → Singapore → Hong Kong; also routes via Taiwan, Thailand, Canada
6. Final arrival AI-related companies in the PRC and Hong Kong

The “SANDKYAN” label

“SANDKYAN” is not a real company brand. It appears only as a cover label. On paper the goods were low-risk “adapters” or “general computer parts,” designed to pass document-only customs review. Classic three-layer divergence: contents, documents, and labels no longer match.

Straw purchasers

A straw purchaser buys to hide the true buyer. Here, multiple U.S. intermediaries allegedly bought NVIDIA GPUs while concealing China-bound intent. Straw buyers often look like ordinary U.S. customers: real addresses, real entities, real cards. That is exactly why end-user diligence is hard.

Statutes and penalty scale

Export Control Reform Act (ECRA)

  • 50 U.S.C. §§ 4801–4852
  • Penalties (50 U.S.C. § 4819)
    • Criminal (willful): up to 20 years imprisonment + up to $1 million fine
    • Civil: $300,000 or twice the transaction value, whichever is greater

Export Administration Regulations (EAR)

  • 15 C.F.R. Parts 730–774
  • Part 744 (end-use / end-user controls) is central here
  • Supplement No. 4 to Part 744: Entity List
  • As of December 2024 Federal Register actions, 140 entities were newly added, including Footnote 5 designations expanding FDPR

H100/H200 exports to Tier 3 destinations including China, Russia, Iran, and North Korea are generally prohibited. Gatekeeper is alleged to have targeted the center of that prohibition.

Foreign Direct Product Rule (FDPR)

Critical for Japanese companies: foreign-made products produced with certain U.S. technology, software, or equipment can still fall under the EAR. Chips made in Japan with U.S. semiconductor equipment, EDA tools, or materials can be EAR-subject. “We’re not a U.S. company” is not a complete defense. I keep returning to that line because it is the one most teams still under-weight.

Smuggling and conspiracy

  • 18 U.S.C. § 554 (smuggling from the U.S.): up to 10 years
  • 18 U.S.C. § 371 (conspiracy): additional exposure

Five red flags for Japanese companies

Red flag 1: Large orders from brand-new companies

One Brooklyn technology company in the case materials was formed on 2 November 2022, weeks after the October 2022 China semiconductor control package.

Action: Check registration dates, capital, and formation history. Escalate unnatural bulk orders from newly formed entities.

Red flag 2: Residential, P.O. box, or shared odd addresses

Reporting described Hao Global LLC using a residential address and a Brooklyn firm sharing a basement with a 24-hour massage parlor.

Action: Physically sanity-check end-user addresses (e.g., Street View). Non-commercial shared addresses need scrutiny.

Red flag 3: Illogical third-country logistics

North Carolina → New York → Singapore → Hong Kong is hard to justify on pure cost/geography. Extra hops when direct shipping is cheaper are a classic diversion signal.

Action: Checklist logistics rationality. Require end-user certificates when multi-hop routing is common.

Red flag 4: Concentrated wires into a single small entity

Hao Global LLC allegedly received over $50 million in PRC wire transfers. That scale into a small Texas firm over seven months is abnormal.

Action: Integrate credit and export-control review. Flag sudden large inbound wires by bank/country/name to compliance automatically.

Red flag 5: Requests to misclassify

Customer requests to “change the HS code” or “use a lower ECCN” are effectively confessions. This case allegedly used low-risk classifications such as “general computer parts” and “adapters.”

Action: HS/ECCN decisions by dual control, not customer dictate. Auto-reconcile invoice / packing list / B/L / declaration consistency.

Five steps for this week

Step 1: Reconfirm EAR and Japanese FEFTA classification

Document product-by-product classification: U.S. content share, FDPR exposure, list controls, and catch-all.

Step 2: Automate restricted-party screening daily

Entity List, SDN, and METI’s Foreign End User List update daily. Weekly manual checks are too slow. AI-assisted continuous screening is now baseline for high-volume traders.

Step 3: Embed a red-flag checklist in the deal flow

Put the five red flags into new-customer onboarding so sales can spot issues early.

Step 4: Make end-use / end-user checks physical, not paper-only

Collect end-user statements, verify sites visually, and when needed confirm with third-country logistics providers. Align contents and documents.

Step 5: Prepare escalation and voluntary disclosure plans

U.S. Voluntary Self-Disclosure (VSD) and Japanese voluntary reporting can reduce penalties. Pre-agree counsel contacts and internal escalation paths.

FAQ

Q1. Why can’t H100/H200 go to China?
They are high-performance GPUs for generative AI training and inference. U.S. policy treats them as high-risk advanced computing items. Since October 2022, China-bound exports have generally been prohibited under EAR Part 744 / Tier 3 frameworks.

Q2. Can Japanese companies face Gatekeeper-style cases?
Yes. FDPR can bring Japan-made semiconductors and AI equipment under EAR jurisdiction. Japan’s FEFTA and Economic Security Promotion Act apply in parallel.

Q3. Whom do we call if a foreign customer looks suspicious?
In Japan: METI Security Export Control Division. In the U.S.: BIS Enforcement Hotline (1-800-424-2980). Internally, automated red-flag detection is recommended.

Q4. Does “we didn’t know” work?
No. Beyond willfulness, U.S. guidance treats knowledge or reason to know as knowledge. Believing customer statements on paper alone is a weak posture.

Q5. Have Yuan and Gong been convicted?
No. They pleaded not guilty and await jury trial. Hsu pleaded guilty on 10 October 2025; sentencing was scheduled for 18 February 2026.

Latest developments as of July 2026

Gatekeeper’s core message, that advanced semiconductors sit inside national security, now runs parallel to Japanese policy. The 16th Japan–India annual summit on 2 July 2026 produced an economic-security joint statement across semiconductors, critical minerals, clean energy, ICT, and pharmaceuticals, with investment on the order of about ¥2 trillion (Prime Minister’s Office of Japan, July 2026). Strategic goods are discussed not only as export yes/no questions but as supply-chain partnership design. Details: Japan–India Summit and economic security. Concrete operational impact on Japanese firms remains partly unsettled and should be watched as ministries institutionalize the framework.

If you want to improve export-control operations or classification efficiency, review the TRAFEED service catalog (PDF) or contact us.

Key takeaways: turn a $160M lesson into operations

Operation Gatekeeper is a December 2025 DOJ–BIS case involving an alleged ~$160M NVIDIA H100/H200 diversion attempt. Public pattern: straw purchase, warehouse aggregation, SANDKYAN label fraud, third-country routing. Alan Hao Hsu of Hao Global LLC entered the first AI-diversion guilty plea of its kind. Other named individuals remain at the not-guilty stage.

Exposure under ECRA runs up to 20 years + $1M. FDPR can reach Japanese firms. The red flags worth wiring into sales tomorrow: new entities, residential addresses, odd routing, concentrated wires, misclassification requests. Five steps: classification, automated screening, red-flag sheet, physical end-use checks, voluntary disclosure plan.

Honestly, doing all of this by hand is not realistic at volume. Lists update daily. Red flags hide in transaction data. Document consistency exceeds human attention spans.

That is where TRAFEED (formerly ZEROCK ExCHECK) is designed to help: METI-aligned and EAR/FDPR-aware classification, automated Entity List / SDN / Foreign End User List screening, and detection of Gatekeeper-style red flags (address anomalies, wire concentration, route risk, misclassification requests) from internal data.

If this piece raised doubt about your red-flag detection, look at a TRAFEED demo.

  • Foreign Direct Product Rule (FDPR) for Japanese companies
  • What BIS budget growth means for enforcement intensity
  • Entity List / MEU List / SDN List in 30 minutes

References

Primary U.S. government sources

Reporting

  • CNBC, “U.S. uncovers scheme to reroute Nvidia GPUs worth $160 million to China despite export bans” (9 Dec 2025)
  • Newsweek, “US Busts Network Smuggling Advanced Nvidia Chips to China”
  • Axios, “2 businessmen detained over scheme to smuggle Nvidia chips to China” (9 Dec 2025)
  • FOX 26 Houston, “Houston-linked 'Operation Gatekeeper' broke $160M A.I. chip smuggling pipeline to China”
  • Washington Times, “DOJ operation busts $160 million network smuggling Nvidia chips to China” (9 Dec 2025)
  • The Wire China, “Chasing the Chip Smugglers” (1 Mar 2026)

Law-firm commentary

  • Arnold & Porter Enforcement Edge on Operation Gatekeeper
  • Morrison Foerster, “Managing Export Control Risks in the AI Chip Ecosystem”
  • Alvarez & Marsal, “AI Technology Export Enforcement: 5 Signals Companies Cannot Afford to Miss”
  • The Export Practitioner, “China-Linked AI Chip Smuggling Network: Many Red Flags”

Japan-side references

  • METI Security Export Control: official page
  • Nagashima Ohno & Tsunematsu, “U.S.-Japan Export Controls and Recent Developments in Practice”

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles