<?xml version='1.0' encoding='utf-8'?>
<!--  Intended for AI agents, to make my writing easier to parse.  -->
<writing author="Tao Burga">
  <last-updated>2026-09-06</last-updated>
  <article>
    <title>How Should the US Prepare for Increasingly Automated AI R&amp;D?</title>
    <subtitle>23 low-regret policy recommendations</subtitle>
    <date>2026-08-06</date>
    <publication>Institute for Progress</publication>
    <authors>Tim Fist; Saif Khan; Tao Burga; Arthur Tellis; Ben Schifman; Jonah Weinbaum; Olivia Scharfman</authors>
    <link>https://ifp.org/preparing-for-ai-research-automation/</link>
    <summary source="Executive summary">In July 2026, over 1,300 employees of frontier AI companies called for the US government to build the capacity to “pace” automated AI R&amp;D via international coordination. The letter entails three specific claims:

Frontier AI companies are close to fully automating AI R&amp;D.
Automating AI research would pose serious risks.
Building the option to “pace” is a good way to address those risks.

In this report, we assess the validity of this argument and its implications for US policymakers. Our findings are as follows:

Rapid progress towards fully automated AI R&amp;D has empirical support, but how much AI capability acceleration this will cause and the risks it might pose are less understood.
Despite substantial uncertainty, we believe some preparatory policy action is warranted. This follows both from the seriousness of the possible direct risks and from the risk of political backlash to AI-driven disruptions resulting in poorly-reasoned policy measures, such as broad bans on new data centers.
The term “pacing” is vague and could encompass many possible policy measures. Any decision to slow down AI progress should not be taken lightly. The benefits of more advanced AI could include accelerated economic growth, new technologies, and scientific breakthroughs such as novel cures for diseases.
Yet, if AI companies succeed in substantially or fully automating AI R&amp;D, and that automation introduces serious risks, the policy tradeoffs would look very different. We propose operationalizing “pacing” to capture this “if-then” conditionality, consisting of:
Specifying which automated AI R&amp;D activities are likely to pose severe risks, with thresholds set based on careful analysis.
If a threshold is exceeded, incentivizing the re-allocation of resources from those activities towards one of two goals:
Accelerating the diffusion of AI capabilities, by allocating compute and talent towards inference and the development of new AI applications, or
Accelerating R&amp;D to make further AI research automation safer, either by improving model safety directly or by boosting societal resilience.
Under this operationalization, a deliberately “paced” form of automated AI R&amp;D might still involve much faster improvements in AI capabilities than today. It also need not entail slowing innovation overall. Mitigating risks may be a precondition for the sustainability of rapid AI progress, and there will be huge value in more broadly diffusing existing AI capabilities.

To help policymakers begin addressing the risks of further automating AI R&amp;D, we propose opting for near-term policies that: (1) focus on serious and irreversible harms, (2) minimize slowdown in the diffusion of existing AI capabilities, (3) have upside even if automated AI R&amp;D and its attendant risks prove unlikely, (4) avoid systematically disadvantaging more cautious companies and countries, and (5) avoid establishing a regulatory apparatus that is likely to be misused.

We then propose 23 specific, preparatory policy measures that meet these criteria, across 7 key areas:

Provide transparency into automated AI R&amp;D

Frontier AI companies and relevant industry bodies should publicly share information relevant to trends and risks in AI R&amp;D automation
Congress should legislate transparency about automated AI R&amp;D risk management, incident reporting, whistleblower protections, and model behavior specifications

Improve state capacity to understand and respond to automated AI R&amp;D

Congress should resource the Center for AI Standards and Innovation (CAISI) with a budget of at least $84 million per year and empower it to directly advise senior government officials and frontier AI companies
The White House should set clear roles and responsibilities of US government agencies to increase specialization across AI policy
Intelligence agencies should improve their collection and analysis on foreign AI development and counter threats targeting US AI companies

Develop a risk management strategy for automated AI R&amp;D that accelerates defensive and commercial AI uses

CAISI should develop guidelines for managing the risks of rapid AI capability improvement

Accelerate the development of AI verification technology

CAISI should co-lead an AI Verification Consortium (AIVEC) with industry to prototype and deploy verification technologies
AIVEC should coordinate the creation of AI hardware testbeds and make them available to government, industry, and nonprofit partners
AIVEC should launch philanthropically funded prize competitions for AI verification headed by CAISI
AIVEC should coordinate the construction of a fully verifiable data center
The Defense Advanced Research Projects Agency (DARPA) and the National Science Foundation (NSF) should set up AI verification R&amp;D programs
Intelligence agencies should develop and operationalize unilateral means of AI compute monitoring

Invest in AI resilience

The National Security Agency (NSA), CAISI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the National Cyber Director (ONCD) should further invest in cybersecurity resilience
Congress, the Office of Science and Technology Policy (OSTP), and the Centers for Disease Control and Prevention (CDC) should invest in biosecurity resilience

Extend the US AI lead to give the US more time to manage AI R&amp;D automation risks

Congress and the Bureau of Industry and Security (BIS) should strengthen controls on US and allied semiconductor manufacturing equipment (SME)
Congress and BIS should close gaps in AI chip controls
The Federal Trade Commission (FTC), Department of Justice (DOJ), BIS, CAISI, and Congress should help industry counter adversarial distillation of US AI model capabilities
BIS should maintain visibility into sales of US chips
The Department of War (DOW), intelligence agencies, CAISI, and relevant Federally Funded Research and Development Centers (FFRDCs) should establish consensus security guidelines for protecting model weights from theft and prototype them in a government facility
Congress should ensure the US has sufficient electrical capacity to sustain AI leadership
Congress should ensure AI infrastructure like data centers can be constructed in America

Create option value for international cooperation on managing automated AI R&amp;D risks

The US government should use its bilateral AI dialogue with China to jointly develop guidelines for managing risks from rapid AI capability growth and prepare verification measures
Countries with national AI institutes should collaborate on automated AI R&amp;D risk management guidelines and technical capacity for AI verification</summary>
  </article>
  <article>
    <title>Do Not Surrender to the Tech Tree</title>
    <subtitle>A defense of human agency in a techno-deterministic world</subtitle>
    <date>2026-02-12</date>
    <publication>Macroscience</publication>
    <authors>Tao Burga</authors>
    <link>https://www.macroscience.org/p/do-not-surrender-to-the-tech-tree</link>
    <summary source="Publisher description">A defense of human agency in a techno-deterministic world</summary>
  </article>
  <article>
    <title>Request for Proposals: The Launch Sequence</title>
    <subtitle>Apply to our rolling effort to find, scope, and build the most important projects to prepare the world for advanced AI</subtitle>
    <date>2026-01-23</date>
    <publication>Institute for Progress</publication>
    <authors>Tao Burga; Jonah Weinbaum; Dan Turner-Evans; Tim Fist; Jay Kim</authors>
    <link>https://ifp.org/rfp-launch/</link>
    <summary source="Summary">This is a Request for Proposals (RFP) to contribute to the next iteration of The Launch Sequence: an initiative to develop projects that prepare the world for advanced AI.
You can use this link to submit a proposal. Your proposal should be a short (200–400 words) pitch for a project that will accelerate science, strengthen security, or adapt institutions in anticipation of widespread advanced AI.
You should submit a proposal if you have a good idea, even if you don’t expect to be the person actually leading or working on the resulting project. However, we’re especially excited about proposals from people who plan to lead projects themselves.
If your proposal is selected, we’ll work closely with you to develop the idea into a concrete project plan, publish your plan, connect you with philanthropic funders, and help you headhunt for a project lead or co-lead.
On top of support from the IFP team, you’ll also have the support of our advisory panel for The Launch Sequence: Tom Kalil (CEO, Renaissance Philanthropy), Matt Clifford (Co-founder and Chair, Entrepreneurs First, and Chair of ARIA), Wojciech Zaremba (Co-Founder, OpenAI), Kathleen Fisher (CEO, ARIA; former DARPA I2O Director), and George Church (Director, Church Lab; co-founder of dozens of biotech startups).
Authors of published proposals will receive a $10,000 honorarium. We are also offering $1,000 bounties for successful referrals and for new ideas that we end up publishing.
This is a rolling RFP with no submission deadline, but we will prioritize early submissions and start reviewing immediately. You may submit multiple pitches.</summary>
  </article>
  <article>
    <title>Should the US Sell Hopper Chips to China?</title>
    <subtitle>Assessing the impacts of exporting the H200 or H100 AI chips</subtitle>
    <date>2025-12-07</date>
    <publication>Institute for Progress</publication>
    <authors>Saif Khan; Tao Burga; Tim Fist; Georgia Adamson</authors>
    <link>https://ifp.org/should-the-us-sell-hopper-chips-to-china/</link>
    <summary source="Executive summary">Last month, the Trump administration decided not to export a version of NVIDIA’s flagship Blackwell AI chips (such as the rumored “B30A” chip) to the People’s Republic of China (henceforth “China”), with President Trump stating “We will not let anybody have [the most advanced AI chips] other than the United States.” Now, the administration is expected to convene a high-level meeting to decide whether to authorize the export of NVIDIA’s H200 chips to China.

Released in March 2024, the H200 is NVIDIA’s best AI chip from the previous “Hopper” generation and is an upgraded version of the H100 chip. Much like cutting-edge Blackwell chips, Hoppers use TSMC’s 4nm manufacturing process technology. Despite being a previous-generation AI chip, the H200 and the H100 will likely be highly useful for frontier AI workloads throughout 2026:

As of December 2025, 18 of the 20 most powerful publicly documented GPU clusters in the world primarily used Hopper chips, including all of the top 7. Hoppers currently represent just over half as much installed AI compute as Blackwells.
Previous generations of AI chips have remained in use for frontier model training for roughly four years. If this trend holds for Hoppers, they will likely be used for frontier training throughout 2026 — especially the H200, which was released in late 2024.

Permitting export of meaningful volumes of advanced Hopper chips to China would have six key implications:

The decision would be a substantial departure from the Trump administration’s current export control strategy, which seeks to deny powerful AI compute to strategic rivals. The H200 would be almost 6x as powerful as the H20 — a chip that requires an export license to China and has been approved for export in only limited quantities.
China would have access to chips that outperform any chip its companies can domestically produce, and at much higher quantities. Huawei is not planning to produce an AI chip matching the H200 until Q4 2027 at the earliest. Even if this timeline holds, China’s severe chip manufacturing bottlenecks mean that it will not be able to produce these chips at scale, reaching only 1–4% of US production in 2025 and 1–2% in 2026.
Chinese AI labs would be able to build AI supercomputers that achieve performance similar to top US AI supercomputers, albeit at a cost premium of roughly 50% for training and 1-5x for inference, depending on workload. Blackwells have been marketed as delivering 30x the inference performance of the H200. However, this multiplier does not account for price differences and reflects best-case assumptions for Blackwell-based clusters and worst-case assumptions for Hopper-based clusters. In an apples-to-apples analysis, we estimate near parity between Blackwells and H200s for many inference workloads; up to a 5x advantage for Blackwells on the type of inference workloads for which they are best suited; and a 1.5x advantage for Blackwell-based clusters in training. This means that with access to Hoppers, Chinese labs could build AI training supercomputers as capable as American ones at 50% extra cost — a premium that the Chinese Communist Party (CCP) would likely at least partly subsidize. The Blackwell advantages could increase if AI developers can exploit its advanced “low-precision” features, which some might do in 2026, but there is not yet evidence that any have done so at scale.
These exports would counterfactually add to China’s total supply of advanced AI compute, and would likely do little to slow China’s indigenization efforts. China’s chip manufacturing bottlenecks mean Huawei’s peak production will still fall well short of domestic demand. Therefore, US chip sales would add to China’s total compute, not substitute for domestic production. Beijing will also likely maintain artificial demand for domestic chips through procurement mandates and restrictions on foreign chips in critical infrastructure, boosting its domestic semiconductor industry regardless of US export control policy.
As summarized in Figure 1, exporting Hopper chips would significantly erode America’s expected AI compute advantage over China. With no AI chip exports to China and no smuggling, we estimate the US would hold a 21–49x advantage in 2026-produced AI compute, depending on whether FP4 or FP8 performance is used for Blackwell chips. This advantage would translate into a much greater American capacity to train frontier models, support more and better-resourced AI and cloud companies, and run more powerful inference workloads for more capable AI models and agents. Unrestricted H200 exports would shrink this advantage to between 6.7x and 1.2x, depending on the scale of Chinese demand and the degree of adoption of FP4.
If supply is constrained, producing Hoppers for China would directly trade off with Blackwell production for the US and allies, since both chip generations compete for much of the same high-bandwidth memory (HBM), logic, and advanced packaging capacity.

We focus on the H200 chip in this report because it is currently under consideration for export to China. But because the H200 chip is essentially a memory-heavy version of the H100 chip, the conclusions drawn in this report largely also apply to H100 chips.</summary>
  </article>
  <article>
    <title>Should the US Sell Blackwell Chips to China?</title>
    <subtitle>Assessing the impacts of exporting the NVIDIA B30A AI chip</subtitle>
    <date>2025-10-25</date>
    <publication>Institute for Progress</publication>
    <authors>Georgia Adamson; Saif Khan; Tao Burga; Tim Fist</authors>
    <link>https://ifp.org/the-b30a-decision/</link>
    <summary source="Executive summary">The United States is reportedly considering whether to permit sales of NVIDIA’s forthcoming B30A chip to China, following lobbying efforts from NVIDIA. The B30A’s reported specifications suggest it will enable roughly equivalent capabilities as NVIDIA’s flagship B300 by delivering half the B300’s performance at half the price. If meaningful volumes of chips with these specifications are permitted to be exported to China, it would have four major implications:

The decision would be a substantial departure from the Trump administration’s current export control strategy, which seeks to deny powerful AI compute to strategic rivals. The B30A would be more than 12 times as powerful as the H20 — a chip that requires an export license to China and has been approved for export in only limited quantities. It would also exceed the United States’ current export control performance thresholds by more than 18 times.
In conditions of supply inelasticity, fewer AI chips would be sold to customers in the United States and the rest of the world. This could occur if global demand for AI chips exceeded manufacturing capacity, or if Chinese companies using B30As stole market share from US companies selling cloud compute, either in China or elsewhere.
Chinese AI labs would have access to AI supercomputers as powerful as those available to US AI labs, at a similar cost. We estimate that a B30A training cluster would cost about 20% more than a training cluster based on NVIDIA’s cutting-edge B300, normalized for equivalent peak processing performance and memory bandwidth. This additional cost could be easily covered by state subsidies.
The United States’ total AI compute advantage over China would shrink dramatically. As shown in Figure 1, we estimate that if all US AI chip exports to China are banned in 2026, with no smuggling, the United States would obtain 31x more AI computing power than China. If B30As are instead approved for export to China, this advantage shrinks to less than 4x. In the most aggressive export scenarios involving sales of the B30A chip and comparable AI chips from all other US AI chip companies, this advantage would flip, with China gaining a 1.1x advantage over the United States.

A key argument for allowing exports of the B30A is that sales would satisfy Chinese demand for AI compute that Huawei and other Chinese chip companies would otherwise fill. By cutting off their market, B30A sales could slow China’s indigenization efforts and its ability to compete with the US chip industry in global markets. However, this argument is flawed, for both supply and demand-side reasons:

Huawei and other Chinese companies cannot meet demand in either domestic or global markets because they cannot produce AI chips at scale. This is due to domestic chip manufacturing bottlenecks created by extensive US and allied export controls on semiconductor manufacturing equipment (SME).
China is likely to create artificial demand for Huawei and other Chinese chip companies, such as by maintaining restrictions on US AI chip imports to critical infrastructure. Therefore, US sales will have minimal effect on their market expansion opportunities.

Restricting the export of powerful AI chips to China, such as the B30A, is the best way to maximize the United States’ AI compute advantage in the short term. The best way to maximize this advantage in the long term is to halt China’s domestic expansion of AI chipmaking. The US can do this by tightening country-wide restrictions on SME, especially by barring all exports of deep ultraviolet (DUV) immersion lithography tools needed to make advanced AI chips. The US government can also tighten enforcement of controls on high-bandwidth memory, a critical component that China needs to make AI chips.</summary>
  </article>
  <article>
    <title>Preparing for Launch</title>
    <subtitle>An introduction to The Launch Sequence: Why shaping AI progress matters, and how to go about it</subtitle>
    <date>2025-08-11</date>
    <publication>Institute for Progress</publication>
    <authors>Tim Fist; Tao Burga; Tim Hwang</authors>
    <link>https://ifp.org/preparing-for-launch/</link>
    <summary source="Opening overview">This essay is the foreword to The Launch Sequence, a collection of concrete, ambitious ideas to prepare the world for advanced AI. These projects need people to build them. Get in touch.

If we zoom out from the debate about the specific capabilities of each new AI model, the historical shape of AI progress is clear: AI capabilities are compounding toward something transformative. Even while today’s agents still fumble long chains of actions, their human-indexed performance across coding, math, tool use, and scientific analysis has been rising at an exponential rate. If more domains continue to fall to these trends, the next decade will see AI reshape the economy, science, and the foundations of national power.

But technological trajectories aren’t fate. AI doesn’t automatically solve the most important problems first, and it won’t neutralize the new risks it creates by default. Many proposals targeted at “maximizing AI’s benefits” while “minimizing its risks” are poorly targeted or sorely lacking in ambition. In this essay, we lay out the basic case for the United States to proactively shape AI progress by accelerating the development of both beneficial and defensive technologies:

AI progress is path-dependent: The sequencing of AI progress matters — where and in what order new capabilities are developed may be just as important as which new capabilities are developed.
Given its position in the AI supply chain, and as the world’s most powerful democracy, the United States has the responsibility to shape AI development towards a path that enables — rather than smothers — human flourishing.

This proactive shaping is not without precedent. From nuclear fission to spaceflight to mRNA, the US has repeatedly changed the trajectory of emerging technologies. In the age of AI, we argue for four guiding principles:

We should take advantage of the “jagged frontier” of AI capabilities
We shouldn’t neglect the costs of stalled progress
We should redesign how many of our scientific institutions work
We should adapt to deep uncertainty while working to reduce it

These principles motivate The Launch Sequence: a collection of concrete, ambitious projects to accelerate science and strengthen security on timelines that matter.</summary>
  </article>
  <article>
    <title>Catalyzing a Golden Age: A Blueprint for Strategic AI R&amp;D Investment</title>
    <subtitle>Response to the OSTP RFI on the Development of a 2025 National AI R&amp;D Strategic Plan</subtitle>
    <date>2025-06-03</date>
    <publication>Institute for Progress</publication>
    <authors>Tao Burga; Tim Fist; Arushi Gupta; Caleb Watney</authors>
    <link>https://ifp.org/catalyzing-a-golden-age/</link>
    <summary source="Introduction">AI has the potential to solve some of humanity’s most pressing problems, from finding treatments for crippling diseases through accelerated drug discovery, to eliminating food insecurity by engineering cheap and plentiful foods, to delivering a new scientific revolution through the discovery of new materials and tools. The artificial intelligence of the future could catalyze a new golden age of growth, prosperity, and abundance. But to effectively harness these capabilities, we must solve two broad problems.

First, these benefits may not come by default or quickly enough, given existing commercial incentives. This may be because a particular application would create public goods, which markets tend to undersupply, or because a research direction is high-risk and requires large upfront investments. For example, markets alone may not create an AI to automate the replication of scientific studies, or to investigate new medical treatments that can’t be patented, or invest in basic research in neuroscience with no immediate commercial applications.

Second, rapidly improving AI capabilities will likely come with risks that industry isn’t sufficiently incentivized to solve. AI systems that can broadly accelerate the pace of medical research could also help engineer biological weapons. Advanced coding agents used throughout the economy to vastly increase productivity could also be put to work, day and night, to find and exploit security vulnerabilities in critical infrastructure. Leading AI labs have some incentives to prevent the misuse of their models, but the offense-defense balance of emerging AI capabilities in areas like cyber and bio is uncertain — private incentives to adequately invest in preventing misuse could be dwarfed by the scale of the risks new AI technologies could impose on the public.

The default path of AI development may not deliver us these benefits, nor protect us from these new threats. Taking the default path means surrendering our future to the shape of the AI technology tree: whatever is easiest and most profitable to build will be built first, with no guarantees that this will lead to human flourishing.

But there is an alternative: the US government, as the R&amp;D lab of the world, has long shaped the direction of technological progress, from investing in clean energy to catalyze the massive advances in solar and wind power we see today, to laying the groundwork for the internet, GPS, and modern computing through decades of federally funded research.

The US government can lead the way to a golden age of AI discovery by promoting the development of technologies that bring us scientific benefits faster, and enhancing technologies for safety and security ahead of the development of potentially destabilizing technologies. This will mean developing new public goods that are only imaginable in a world with advanced AI; investing in AI-accelerated vaccine discovery before AI systems can help engineer biological weapons; and investing in automated code refactoring to harden our critical cyber infrastructure before superhuman AI hackers are developed.

Below, we outline key areas where we expect targeted federal R&amp;D investments to yield exceptionally high returns, either by developing new public goods that would not be properly incentivized by market forces alone or by accelerating the development of technologies that would increase our civilizational resilience to new threats.</summary>
  </article>
  <article>
    <title>Conditional Export Controls on AI Chips</title>
    <subtitle />
    <date>2025-04-04</date>
    <publication>The Techno-Industrial Policy Playbook</publication>
    <authors>Tao Burga</authors>
    <link>https://www.rebuilding.tech/posts/conditional-export-controls-on-ai-chips</link>
    <summary source="Summary">The Bureau of Industry and Security (BIS) implements US export controls on dual-use technology. To be effective at preventing misuse and smuggling, some of these controls, such as those on AI chips, must restrict exports to dozens of countries. Although this blanket-ban approach weakens US industry's competitiveness in the short and long term, current oversight and enforcement mechanisms leave little alternative.

Conditional export controls offer a more effective approach within BIS's authorities. This approach allows BIS to specify the conditions under which export restrictions apply, increasing restrictions on technologies that are easy to smuggle or misuse, but not on those that include security features to enable better oversight or reduce misuse potential. This would incentivize AI chip firms to develop more secure versions of their chips in order to avoid tougher export restrictions.

Using the pressing case of AI chips, BIS should reform the Low Processing Performance (LPP) license exception to lower the yearly cap of AI chip exports to single firms, while allowing chip firms to use LPP's current (higher) cap for chips that include security features to help detect or prevent smuggling and/or hinder their misuse. By linking export access to security features, conditional export controls would enhance national security, help sustain US technological leadership, reduce smuggling, and drive security-focused innovation — all without additional government spending.</summary>
  </article>
  <article>
    <title>The H20 Problem: Inference, Supercomputers, and US Export Control Gaps</title>
    <subtitle>How to prevent 1.3 million AI chips from being sold to China today, and how to prepare for the future</subtitle>
    <date>2025-04-15</date>
    <publication>Institute for Progress</publication>
    <authors>Tao Burga; Arushi Gupta; Tim Fist</authors>
    <link>https://ifp.org/the-h20-problem/</link>
    <summary source="Summary">The United States is on the verge of repeating a critical strategic error. Despite having the legal authority and policy tools to constrain China’s access to advanced AI chips, the US government is failing to enforce existing export controls or adapt them to new threats. As a result, Chinese firms are exploiting loopholes to acquire powerful US hardware, undermining America’s lead in frontier AI.

The most immediate risk is the pending export of over 1.3 million NVIDIA H20 chips, worth more than $16 billion, to Chinese tech giants including ByteDance, Alibaba, and Tencent. These chips — optimized for AI inference — are likely to be used in Chinese supercomputers, violating US export controls. At least one of the buyers, Tencent, has already installed H20s in a facility used to train a large model, very likely in breach of existing controls restricting the usage of chips in supercomputers exceeding certain thresholds. DeepSeek’s supercomputer used to train their V3 model is also likely in breach of the same restrictions.

This failure is part of a broader pattern:

Huawei stockpiled restricted chip components, including chip dies and high-bandwidth memory (HBM), before controls took effect.
TSMC has facilitated production of over three million cutting-edge chip dies directly for Chinese firms for Chinese AI efforts, sometimes in violation of US rules.
DeepSeek, a Chinese lab, trained state-of-the-art models using American chips sold legally due to delayed restrictions.

The rationale behind export controls remains sound: allowing China to develop frontier AI using cutting-edge chips is an avoidable national security risk. But the administration of export controls is failing to keep pace with new developments in the field. Inference — once seen as secondary — has become central to training, fine-tuning, and increasing the capabilities of deployed models. The H20, a chip specialized in inference, is already 20% faster than the H100 (a currently banned chip) for inference tasks.

To avoid another preventable failure, the US must act now. We recommend that:

BIS should immediately block the H20 shipments using its existing authority under 15 CFR § 744.23.
NVIDIA must investigate and halt transactions that raise legal red flags under its “Know Your Customer” obligations.
BIS should update export controls to cover inference chips.
The White House should empower a technical team — ideally within the AI Safety Institute (AISI) at NIST — to forecast AI threats and proactively shape control policy.
BIS should track chips once exported to high-risk locations by incentivizing industry adoption of chip geolocation features.

The US retains its technological edge — but its advantage is shrinking, and its policy posture is reactive. Without better foresight and enforcement, American technologies will continue fueling China’s ascent in AI.</summary>
  </article>
  <article>
    <title>An Action Plan for American Leadership in AI</title>
    <subtitle>12 recommendations for the Office of Science and Technology Policy's AI Action Plan</subtitle>
    <date>2025-03-17</date>
    <publication>Institute for Progress</publication>
    <authors>Tim Fist; Tao Burga; Arushi Gupta; Jeremy Neufeld</authors>
    <link>https://ifp.org/an-action-plan-for-american-leadership-in-ai/</link>
    <summary source="Introduction">Recent developments in AI suggest that a new age of scientific discovery and economic growth is within reach. As the R&amp;D lab of the world, the United States is at the frontier of these technologies, and thus has an essential role to play in shaping the future. Emerging technologies are highly path-dependent, and we need to ensure that advances in AI are compatible with American values, and don’t enable authoritarianism or serious national security risks. We focus our response on six areas:

Making it easier to build AI data centers and associated energy infrastructure
Supporting American open-source AI leadership
Launching R&amp;D moonshots to positively shape the development of advanced AI
Establishing a fast and effective national security-focused model evaluation capacity
Attracting and retaining superstar AI talent
Improving export control policies and enforcement capacity</summary>
  </article>
  <article>
    <title>Technology to Secure the AI Chip Supply Chain: A Working Paper</title>
    <subtitle>Toward a Better Balance of Competitiveness, Security, and Privacy</subtitle>
    <date>2024-12-11</date>
    <publication>Center for a New American Security</publication>
    <authors>Tim Fist; Tao Burga; Vivek Chilukuri</authors>
    <link>https://www.cnas.org/publications/reports/technology-to-secure-the-ai-chip-supply-chain-a-primer</link>
    <summary source="Executive summary">Advanced artificial intelligence (AI) systems, built and deployed with specialized chips, show vast potential to drive economic growth and scientific progress. As this potential has grown, so has debate among U.S. policymakers about how best to limit emerging risks. In some cases, this concern has driven significant policy shifts, most notably through sweeping export controls on AI chips and semiconductor manufacturing equipment sold to China. However, AI-focused chip export controls are challenging to target well. Since chip exporters and officials at the U.S. Department of Commerce currently have no reliable means of understanding who is in possession of AI chips after they have been exported, today’s controls are applied in a blanket fashion, without regard to end use or end user. Furthermore, because AI chips and AI algorithms improve over time, the quantity and quality of AI hardware required to develop a model with a particular set of dangerous capabilities will decrease over time. This means that to fulfill their goals of limiting access to specific capabilities, AI export controls must steadily grow in scope, becoming ever more burdensome on exporters and end users. Today’s controls are also difficult to enforce using the current process. Enforcement relies on exporters checking buyers against an official roster of blacklisted organizations maintained by the Bureau of Industry and Security within the U.S. Department of Commerce. Evading this process is straightforward: shell companies can typically be set up online for a few thousand dollars in a matter of hours or days, whereas it can take years of investigation to uncover a shell company’s illicit activities and add them to the list.

At the same time, in the absence of export controls, ensuring that advanced AI technologies are not used for malicious purposes by state and nonstate adversaries could require an intrusive surveillance regime with deleterious consequences for U.S. economic competitiveness and the preservation of democratic values. As policymakers consider how to balance security, competitiveness, and a commitment to democratic values, there is growing interest in technological solutions that can strike a better trade-off between these objectives and keep pace with fast AI progress and the rapidly evolving security landscape. Hardware-enabled mechanisms (HEMs)—mechanisms built into data center AI hardware to serve specific security and governance objectives—have especially attracted interest as a promising new tool.

Variants of HEMs are already widely used in defense products, but also in commercial contexts: On Apple’s iPhone, HEMs ensure that unauthorized applications cannot be installed. Google uses an HEM-based solution to remotely verify that chips running in their data centers have not been compromised. Many video games use a hardware device called a “trusted platform module” as an HEM-based approach to prevent in-game cheating. In the commercial AI space, HEMs are used to distribute training between different users while preserving privacy of code and data.

Well-designed HEMs for AI hardware could help detect and deter AI chip smuggling into China; allow more surgical applications of export restrictions, reducing the risk of a de-Americanization of chip supply chains; and create privacy-preserving, trustworthy, and commercially viable solutions to governance and security issues.

However, the category of HEMs covers a broad design space, with both desirable and undesirable possibilities. For example, the Apple Secure Enclave security module (found in iPhones and MacBooks) is a highly reliable HEM that prioritizes customer security and privacy. This module ensures that only legitimate firmware and operating systems can be used on the device, which in turn helps deter theft and prevent unauthorized applications from being installed. On the other hand, the National Security Agency’s infamous Clipper chip carried severe privacy and security vulnerabilities. While purportedly designed to increase security, the device contained a built-in back door that allowed government officials to access private data.

To advance research, development, and debate around the potential of HEMs to advance AI safety and governance, the authors recommend that U.S. policymakers:

Accelerate HEM and hardware security research and development (R&amp;D) through direct funding and public-private partnerships. The National Semiconductor Technology Center (NSTC), relevant Defense Advanced Research Projects Agency (DARPA) projects, the Department of Defense’s Microelectronics Commons, and the National Institute of Standards and Technology (NIST) could serve as key funders and facilitators of public-private coordination to advance HEM development.
Create commercial incentives for industry HEM R&amp;D through conditional export licensing. The Department of Commerce should incentivize and derisk industry HEM R&amp;D by defining a set of hardware security and governance features that would prevent new restrictions from applying to exported hardware, if those features were installed.
Further develop AI hardware security standards to incentivize and harmonize security features across industry. NIST, in collaboration with industry, the NSTC, and standard-setting bodies like the Institute of Electrical and Electronics Engineers AI Standards Committee and the International Organization for Standardization, should build on existing technical standards to further improve data center AI hardware security, with input from leading semiconductor and security firms.</summary>
  </article>
</writing>
