{
  "schema_version": "1.2.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "O-0207",
    "slug": "center-for-a-new-american-security",
    "title": "Center for a New American Security",
    "aliases": [
      "CNAS"
    ],
    "status": "published",
    "last_reviewed": "2026-09-25",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": [
        "codex-review"
      ]
    },
    "risk_flags": [],
    "flags": [],
    "kind": "research-org",
    "homepage": "https://www.cnas.org/",
    "one_liner": "A nonprofit national-security policy organization; publisher of a report proposing on-chip mechanisms, including location verification, for governing AI chips.",
    "sources": [
      {
        "source": "S-3612",
        "supports": "independent bipartisan nonprofit producing national-security and defense policy"
      },
      {
        "source": "S-0056",
        "supports": "Secure, Governable Chips: security module, staged rollout, hardening, development effort, location verification, ownership tracking"
      },
      {
        "source": "S-3382",
        "supports": "2025 working paper: smuggling estimate for 2024; recommended location verification and notification of exports and ownership transfers"
      }
    ],
    "type": "organization",
    "url": "https://trustbutveri.fyi/organizations/center-for-a-new-american-security/",
    "source_file": "content/organizations/center-for-a-new-american-security.md",
    "flags_all": [],
    "body_markdown": "CNAS describes itself as an independent, bipartisan, nonprofit organization that develops national security and defense policies [[S-3612]]. Its 2024 report *Secure, Governable Chips*, by Aarne, Fist and Withers, proposes on-chip mechanisms for governing AI chips [[S-0056]]:\n\n- **Hardened security module.** The report proposes a module that enforces valid firmware and up-to-date operating licenses and supports remote attestation, rolled out in stages from firmware changes to tamper-evident and then tamper-proof hardware [[S-0056]]. See [[M-0009]], [[M-0011]] and [[M-0008]].\n- **Hardening and effort.** It judges that existing on-chip features must be hardened before they can be relied on in adversarial settings, and estimates that leading firms could build the required functionality with 18 months to 4 years of effort [[S-0056]].\n- **Location verification.** It illustrates ping-based checks with a landmark server in Paris: a reply within 9 ms would place a chip inside a circle that excludes countries subject to export restrictions [[S-0056]]. It expects hundreds of landmarks worldwide [[S-0056]]. See [[M-0018]].\n- **Ownership tracking.** It writes that on-chip mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and know-your-customer policies [[S-0056]]; see [[M-0019]].\n\nA 2025 CNAS working paper by Grunewald, of IAPS, and Fist estimates that between 10,000 and several hundred thousand AI chips, with a median estimate of about 140,000, may have been smuggled to China in 2024 [[S-3382]]. It recommends that chip designers implement software-based location verification, and that the US Bureau of Industry and Security require notification of exports, re-exports and ownership transfers of controlled AI chips [[S-3382]].",
    "body_text": "CNAS describes itself as an independent, bipartisan, nonprofit organization that develops national security and defense policies [S-3612]. Its 2024 report Secure, Governable Chips, by Aarne, Fist and Withers, proposes on-chip mechanisms for governing AI chips [S-0056]: - Hardened security module. The report proposes a module that enforces valid firmware and up-to-date operating licenses and supports remote attestation, rolled out in stages from firmware changes to tamper-evident and then tamper-proof hardware [S-0056]. See Hardware-enabled guarantees (flexHEG) and guarantee processors, Hardware performance throttling and licensing and TEE remote attestation for AI workloads. - Hardening and effort. It judges that existing on-chip features must be hardened before they can be relied on in adversarial settings, and estimates that leading firms could build the required functionality with 18 months to 4 years of effort [S-0056]. - Location verification. It illustrates ping-based checks with a landmark server in Paris: a reply within 9 ms would place a chip inside a circle that excludes countries subject to export restrictions [S-0056]. It expects hundreds of landmarks worldwide [S-0056]. See Chip location verification. - Ownership tracking. It writes that on-chip mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and know-your-customer policies [S-0056]; see Chip registries and manufacturing records. A 2025 CNAS working paper by Grunewald, of IAPS, and Fist estimates that between 10,000 and several hundred thousand AI chips, with a median estimate of about 140,000, may have been smuggled to China in 2024 [S-3382]. It recommends that chip designers implement software-based location verification, and that the US Bureau of Industry and Security require notification of exports, re-exports and ownership transfers of controlled AI chips [S-3382].",
    "referenced_by": [
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0011",
        "title": "Hardware performance throttling and licensing",
        "url": "https://trustbutveri.fyi/mechanisms/hardware-performance-throttling/"
      },
      {
        "id": "S-0056",
        "title": "Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing",
        "url": "https://trustbutveri.fyi/sources/aarne-secure-governable-chips/"
      },
      {
        "id": "S-3612",
        "title": "Center for a New American Security: Mission",
        "url": "https://trustbutveri.fyi/sources/cnas-mission/"
      },
      {
        "id": "S-3382",
        "title": "Countering AI Chip Smuggling Has Become a National Security Priority",
        "url": "https://trustbutveri.fyi/sources/grunewald-countering-ai-chip-smuggling/"
      }
    ]
  }
}