Center for a New American Security
A nonprofit national-security policy organization; publisher of a report proposing on-chip mechanisms, including location verification, for governing AI chips.
www.cnas.org · also called CNAS
CNAS describes itself as an independent, bipartisan, nonprofit organization that develops national security and defense policies 1. Its 2024 report Secure, Governable Chips, by Aarne, Fist and Withers, proposes on-chip mechanisms for governing AI chips 2:
- Hardened security module. The report proposes a module that enforces valid firmware and up-to-date operating licenses and supports remote attestation, rolled out in stages from firmware changes to tamper-evident and then tamper-proof hardware 2. See Hardware-enabled guarantees (flexHEG) and guarantee processors, Hardware performance throttling and licensing and TEE remote attestation for AI workloads.
- Hardening and effort. It judges that existing on-chip features must be hardened before they can be relied on in adversarial settings, and estimates that leading firms could build the required functionality with 18 months to 4 years of effort 2.
- Location verification. It illustrates ping-based checks with a landmark server in Paris: a reply within 9 ms would place a chip inside a circle that excludes countries subject to export restrictions 2. It expects hundreds of landmarks worldwide 2. See Chip location verification.
- Ownership tracking. It writes that on-chip mechanisms would need a way to track who owns data-centre AI chips, supported by supply-chain tracking and know-your-customer policies 2; see Chip registries and manufacturing records.
A 2025 CNAS working paper by Grunewald, of IAPS, and Fist estimates that between 10,000 and several hundred thousand AI chips, with a median estimate of about 140,000, may have been smuggled to China in 2024 3. It recommends that chip designers implement software-based location verification, and that the US Bureau of Industry and Security require notification of exports, re-exports and ownership transfers of controlled AI chips 3.
On this page
Related records
Mechanisms and implementations whose records cite or describe this organization's work.
- Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.
- On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.
- Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.
Publications
Sources this organization authored or published.
- BCenter for a New American Security: Mission. Center for a New American Security. Source recordCited by Center for a New American Security
- BE. Grunewald & T. Fist (2025). Countering AI Chip Smuggling Has Become a National Security Priority. Center for a New American Security (working paper). Source recordCited by Chip registries and manufacturing records; Chips are where they are declared to be; Center for a New American Security
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordCited by Chip location verification; Chip registries and manufacturing records; Hardware-enabled guarantees (flexHEG) and guarantee processors; Hardware performance throttling and licensing; TEE remote attestation for AI workloads; Hardware-enabled mechanism (HEM); Center for a New American Security
Sources
- BCenter for a New American Security: Mission. Center for a New American Security. Source recordSupports: independent bipartisan nonprofit producing national-security and defense policy
- BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: Secure, Governable Chips: security module, staged rollout, hardening, development effort, location verification, ownership tracking
- BE. Grunewald & T. Fist (2025). Countering AI Chip Smuggling Has Become a National Security Priority. Center for a New American Security (working paper). Source recordSupports: 2025 working paper: smuggling estimate for 2024; recommended location verification and notification of exports and ownership transfers