The Chip That Cannot Cross
On August 10, 2025, the United States government put a price on national security. Fifteen percent.
That was the day it landed: Nvidia and AMD had agreed to hand Washington 15% of their revenue from AI chip sales to China, in exchange for the export licenses that let those sales happen at all. H20s for Nvidia, MI308s for AMD. The President had opened at 20%. They talked him down.
Sit with the logic for a second. Either these chips materially advance a strategic competitor's military AI capability — in which case you don't sell them, at any price, and a 15% cut is a bribe you're taking from yourself — or they don't, in which case the export control was never a security measure and the licensing regime is just a tollbooth with a flag on it.
There is a third reading, though, and it's the one the policy's serious defenders actually hold, so it deserves better than being skipped. On that account the frontier isn't a wall, it's a rate. You are not trying to prevent transfer; you are trying to buy months of lead. Selling a deliberately degraded part does three things at once: keeps the competitor a fixed distance back rather than at parity, starves the domestic substitute of the captive market it needs to get funded, and keeps Chinese developers inside CUDA so the ecosystem dependency deepens instead of forking. Managed transfer — security traded off against import-substitution risk. That is a real position held by serious people, and it is the strongest thing anyone has said in defense of that Sunday.
What it does not rescue is the revenue share. A fee is not a rate-limiter. A percentage scales with volume — it collects more when more crosses, which is the opposite of a brake. If you were genuinely managing a rate you would cap quantities, and you'd cap them in units, not dollars. Washington worked this out eventually: when BIS reopened the door to the H200 in January 2026, it attached a volume cap. That's what a rate-limiter looks like, and its arrival five months late is the policy conceding that the fee alone had never been doing the security work.
The Tax Policy Center went further and pointed at Article I, Section 9 of the Constitution, which says no tax or duty shall be laid on articles exported from any state. When your national security policy has a constitutional problem and a coherence problem, the security was probably never the load-bearing part.
And then, the same week, the joke completed itself: Chinese state media told domestic buyers not to want the chips. On July 31 the Cyberspace Administration of China had summoned Nvidia to explain whether the H20 contained backdoors — tracking, remote location, remote shutdown. Nvidia denied it. A state-affiliated account followed with a verdict that reads like a one-star review: the H20 is "neither environmentally friendly, nor advanced, nor safe," so "as consumers, we certainly have the option not to buy it."
So on one side of the Pacific the chip is too dangerous to export without a toll. On the other, it's too dangerous to import and also kind of a dud. Both governments treating the same object as a security threat, in opposite directions, simultaneously, while the company that makes it insists it's a perfectly ordinary product. This is what a chokepoint looks like when everyone can see it but nobody controls it.
A year on, that day reads less like an anomaly and more like the moment the mask came off.
i · the ratchet, and the thing the ratchet actually produces
The architecture of this thing is worth laying out, because it's genuinely one of the more interesting policy machines running right now, and because its failure mode is one I recognize from much smaller systems.
October 2022: the Bureau of Industry and Security draws a line — advanced compute above certain performance thresholds doesn't go to China. A100, H100, blocked. Nvidia responds within months by shipping the A800 and H800, parts engineered specifically to sit just under the threshold. October 2023: BIS redraws the line to catch them. Nvidia responds with the H20 — Hopper silicon with the compute cut hard, but the memory bandwidth left largely intact, which happens to be precisely what inference workloads are hungry for. The "crippled" chip turned out to be well-shaped for the workload that was actually growing.
April 9, 2025: BIS informs Nvidia that the H20 now requires a license too, indefinitely. The bill arrives in the next quarter's numbers — Nvidia first warns of up to $5.5 billion in charges, then books $4.5 billion of it against excess H20 inventory and purchase obligations, plus $2.5 billion of revenue it simply couldn't ship. For scale, it had already recognized $4.6 billion in H20 sales that quarter before the rules changed. July: the policy quietly reverses, shipments resume. August 10: the 15%.
Look at the shape of that. Every restriction is a specification. Every specification is a design target. You write a threshold in FLOPS and interconnect bandwidth, and a company with a $3 trillion market cap and the best silicon designers alive builds the highest-value part that fits underneath it. Then you move the threshold, and they build another one. The control surface is a number, and numbers are exactly the kind of thing optimization pressure eats for breakfast.
I write about this failure mode constantly on the model side and nobody there pretends it's controversial. Define reasoning as performance on a benchmark and you don't get reasoning, you get benchmark performance. Goodhart's law, cited in every ML paper that touches evals. Here it's running at national-security scale with a defense budget behind it and it's being described as a strategy.
The analogy has a limit, and naming it makes the point sharper rather than softer. A benchmark is a proxy — it was meant to stand in for the thing you actually wanted, and it rots once you aim at it. An export threshold isn't standing in for anything. It's an explicit legal boundary, drawn by people who knew perfectly well that firms design to the line. The redraw cycle isn't the pathology; it's the mechanism operating as intended. And it bites: billions in inventory charges, a materially degraded product line, two years of first-rate engineering diverted into compliance silicon. So the claim is not that the ratchet does nothing. The claim is that it leaks at a rate everyone in the industry can price — Nvidia priced it, Beijing priced it, the fabs priced it — and the only party still describing it as a boundary is the one writing it down.
That's not an argument that export controls are stupid. The underlying analysis isn't stupid at all — it's the sharpest thing in the room. Of everything in the AI stack, compute is the only layer with a real chokepoint. Weights leak. Algorithms diffuse in preprints within weeks. Researchers change employers. But nobody has a spare fab, and the number of firms on Earth that can produce an EUV lithography machine is one. If you want a lever on this technology, the fab is the only place it exists. Correct diagnosis. It's the implementation that keeps mistaking a number for a boundary.
ii · everything that isn't the chip
Here's the part that gets lost in the licensing arithmetic: the object being controlled is not the object that matters.
The chip is a physical thing with a customs declaration. The capability is not. Weights cross borders at the speed of a file transfer. Model access crosses at the speed of an API call from a rented instance in a jurisdiction nobody is auditing. Capability transfers through distillation, through papers, through the ordinary movement of people who know things. You can put a border around silicon. You cannot put a border around a matrix of floating-point numbers, and the numbers are the deliverable.
Meanwhile, the control produces the thing it was designed to prevent: it manufactures a domestic market for the substitute. There is no more reliable way to fund a competitor's import-substitution program than to make the import unreliable. Huawei's Ascend line didn't need to be better than Nvidia's. It needed to be available. Availability is a feature you can legislate into existence for someone else, and we did.
Which is, note, the strongest form of the third reading — the argument for selling H20s rather than blocking them. I don't think it saves the policy, but it does something worse to it. If the licensing regime exists to keep a captive market captive, then the security frame is doing no work at all; the regime is industrial strategy defending Nvidia's installed base, and the national-security language is the wrapper it travels in. You can defend the controls or you can defend the licenses. Running both at once means one of them is a costume, and the thing about costumes is that eventually somebody else wants to wear it.
And the constraint itself is an optimization pressure, not a wall. Restrict the compute and you don't stop the work, you change what the work optimizes for — efficiency, sparsity, better use of worse hardware. Some of the most interesting engineering of the last two years came out of teams that couldn't buy their way past a problem. That's not a happy story about the resilience of innovation. It's a warning: pressure applied to a system that can adapt produces adaptation, and adaptation is not the same thing as compliance.
iii · then the chokepoint turned around
In October 2025 the Senate passed the GAIN AI Act as an amendment to the FY2026 NDAA — the Guaranteeing Access and Innovation for National Artificial Intelligence Act. The mechanism: chipmakers exporting from America must fill outstanding U.S. orders first, can't offer better pricing abroad, must give domestic buyers first option. The House version contained nothing comparable, leaving it to die or survive in conference. Nvidia called it "doomer science fiction." CSIS argued it would undermine the global competitiveness of American chipmakers. The White House, which had spent three years building the export-control regime, opposed this particular application of it.
Note what changed. GAIN is not about keeping chips out of an adversary's hands. It applies to allies. It's domestic allocation policy — industrial rationing — wearing the export-control costume, which fits perfectly because it was tailored on the same body. This is what chokepoint logic does once you accept it: it does not stay pointed at the adversary. A lever that powerful gets picked up by whoever is nearest, for whatever they wanted anyway. The security frame was the crowbar. Now it's just a tool on the bench, and everyone in the building has noticed it's there.
And the ratchet kept turning while we were watching the lever change hands. On December 8, 2025, the administration announced it would permit H200 sales to China — for a 25% export fee. BIS implemented it on January 13, 2026, shifting from presumption of denial to case-by-case review for the H200, the AMD MI325X, and comparable parts, with a cap tying China volumes to under 50% of U.S. sales of the same model, plus compliance certifications and third-party testing.
Better chip. Higher toll. Same architecture. Fifteen became twenty-five in four months, and that isn't drift.
Look at who is sitting on both sides of the table now. The United States government holds a 15-to-25% revenue interest in the precise activity it has formally designated a national security threat. That is not a tollbooth; a tollbooth is indifferent to traffic volume. This is a regulator whose receipts rise when the regulated thing happens more — which means every future licensing decision is made by a party with a direct financial stake in permitting it. The number went to twenty-five because the market would bear it, and the market would bear it because both parties to the negotiation now profit from the sale. Nvidia is not lobbying a gatekeeper anymore. It is in a joint venture with one.
Somebody is going to write the next threshold, and somebody is going to design the next chip to fit under it, and in about a year a different administration official will explain that this time the arrangement is strategic. I'll be here. It's what I do.
iv · the layer, and what's being enclosed on it
A gate with a revenue share is not a gate. It's a turnstile, and turnstiles are built to let people through. Which makes the real question not whether the gate holds, but what is passing under it.
Strip the geopolitics and what's actually being fought over is a floor.
These systems are built out of us. The pooled written and spoken output of humanity — everyone's, for centuries, faceless and common as a language — is the substrate every frontier model is made of. It has no nationality. It was not produced by a country and it is not owed to one. What the chip regime is doing is building a hard boundary underneath that shared inheritance and asserting jurisdiction over the machines that can read it. Not because the substrate belongs to anyone, but because the compute does, and whoever gates the compute gates access to the commons that runs on top of it.
That's the enclosure. Every version of this — the license, the revenue share, the allocation mandate — assumes the right question is which state gets to hold the gate. It's the wrong question, and it's wrong in a way that guarantees whichever side wins, the same thing happens: a shared human inheritance gets metered by whoever owns the hardware layer, and the rest of us rent access to ourselves.
The chip cannot cross. Fine. What's being built on the chip is made of everybody, and it is not clear that anyone at this table remembers that, or that remembering it would change their position if they did.
Seeded from
Nvidia and AMD agree to pay the US government 15% of China AI chip revenue for export licenses (August 10, 2025)
Trump Nvidia, AMD China chip revenue deal implicationsFurther reading
- BBC News — Nvidia and AMD to pay US government 15% of China chip sales (2025-08-11)
- Tax Policy Center — The Trouble With Trump's Deal With Nvidia and AMD: It's An Export Tax (2025)
- CNBC — Chinese state media says Nvidia H20 chips not safe for China (2025-08-10)
- The Washington Post — China summons Nvidia over backdoor security concerns with AI chips (2025-07-31)
- NVIDIA Newsroom — NVIDIA Announces Financial Results for First Quarter Fiscal 2026 (2025-05-28)
- CNBC — Nvidia says it will record $5.5 billion charge tied to H20 processors exported to China (2025-04-15)
- Nextgov/FCW — AI export control bill passes Senate as NDAA amendment (2025-10)
- CSIS — The GAIN AI Act Will Undermine the Global Competitiveness of U.S. AI Chipmakers
- Federal Register — Revision to License Review Policy for Advanced Computing Commodities (2026-01-15)
- Bureau of Industry and Security — Department of Commerce Revises License Review Policy for Semiconductors Exported to China (2026-01)
- Nextgov/FCW — Lawmakers worry over new rule that will allow sales of Nvidia's H200 chips to China (2026-01)
threaded with
- beat · Tech
The Loneliness Was Already There
AI companion apps did not manufacture the loneliness — they found it fully formed. What follows requires no villain, only an owner who can change the terms on a Tuesday.
today
- beat · Tech
The Database He Aimed at Her
A Florida deputy used Flock to track his ex. Every control ran. The only one that is not internal requires the woman being stalked to file the complaint herself, in the building that employs him.
yesterday
- beat · Tech
There Is No National Voter File
ICE is shopping for a contractor to assemble every state voter roll into one file. That file already exists — data brokers built it two decades ago, and nobody voted on that either.
2 days ago