Export Controls Assume a Chokepoint. Two and a Half Billion Dollars of Servers Went Straight Through It.
Washington's China strategy assumes advanced chips can be physically controlled. The indictments describe a pipeline around that assumption — and one chokepoint it never touched.
The last time I moved countries, I declared forty-one boxes to customs and I did not tell the truth about all of them. Not criminally — lazily. Somewhere around box nineteen an honest inventory (books, kitchen appliances, my grandfather's tools) became "household goods," because that is the phrase the form wants.
Nobody opened box nineteen. Nobody opened any of them. The control on that shipment was never a person looking inside a container. It was me, writing two words, and a system that had decided in advance to believe me.
I have been thinking about those boxes since March 19, 2026 — and before this goes further, I have to correct my own headline.
Prosecutors do not allege that $2.5 billion of servers reached China. The only China-diverted figure the government commits to is at least approximately $510 million, in a three-week window. The $2.5 billion is what a Southeast Asian pass-through company purchased from a US manufacturer across 2024 and 2025; the charging document says a substantial portion of that revenue came from machines subsequently diverted.
Two different claims. I wrote the headline; most of the coverage merged the numbers, and a merged number is not a court document, it is a vibe.
Housekeeping: nobody here has been convicted of anything. The Justice Department says so itself — the charges are "merely accusations, and the defendants are presumed innocent unless and until proven guilty." Super Micro's co-founder, Yih-Shyan "Wally" Liaw, has pled not guilty, per the Taipei Times. Supermicro is not a defendant. Neither is Nvidia. Both appear as context only.
So far so good. Now the part that keeps me up.
The part that is written down
American policy on advanced AI hardware rests on a premise so basic almost nobody says it out loud: that the object can be stopped. The Justice Department's announcement states it plainly — chips of this class and the servers containing them require licenses for transfer to China and Hong Kong, under rules reflecting "a formal determination" that such transfers pose "an unacceptable risk to national security." Read that as an engineering claim rather than a policy one: this particular object must not move.
The indictment unsealed in Manhattan federal court on March 19, 2026 describes three men who allegedly treated that as a routing problem. Liaw, a US citizen; Ruei-Tsang "Steven" Chang and Ting-Wei "Willy" Sun, both citizens of Taiwan, were charged with conspiring to divert high-performance servers to China in violation of export control laws. Liaw and Sun were arrested that day. Chang remains a fugitive — never arrested, which I flag because the shorthand version routinely says three men were taken into custody.
The route
The alleged pipeline's most striking feature is how boring each leg is.
Servers were assembled in the United States and shipped to the manufacturer's facilities in Taiwan, then on to a pass-through company — the indictment calls it Company-1 and locates it only "elsewhere in Southeast Asia," which is where I will leave it, because press speculation is not sourcing. From there, prosecutors allege, they were routed to purchasers in China through what the government calls "a rotating cast of third-party brokers."
Each movement, on paper, was an ordinary commercial shipment. Nothing was smashed, no fence was cut. What was allegedly falsified is the answer to the question my customs form asked: where is this going, and who is receiving it?
Then, per the same announcement, Company-1 used a logistics firm to repackage the servers into unmarked boxes before the final leg. The identifying marks came off in a warehouse, not a laboratory. At no point, prosecutors say, did anyone here hold a Commerce Department license to export those servers to China.
John A. Eisenberg, Assistant Attorney General for National Security, summarized the alleged method in a sentence I cannot shake: "false documents, staged dummy servers to mislead inspectors, and convoluted transshipment schemes, in order to obfuscate the true destination of restricted AI technology—China." Notice what is absent. No hacking, no theft, no breached wall. It is a description of a logistics operation.
The audit, and then the inspection
Two separate inspections appear in the record, and they are constantly collapsed into one. They should not be.
The first was the manufacturer's own compliance audit in August 2025, for which prosecutors allege the defendants staged thousands of "dummy" servers — non-working physical replicas — where Company-1 was supposedly storing what it had bought.
The second was a US Department of Commerce inspection. For that one, prosecutors allege Sun and a broker re-staged some of those same dummies: unboxing them, using a hair dryer to remove and affix labels and serial number stickers, then repacking them in the manufacturer's cartons.
I dwell on the hair dryer because it is not a detail, it is a thesis. The United States built an elaborate legal architecture around the proposition that certain silicon must not cross a line. On the other side of it, in the government's telling, sits a warehouse, a stack of empty cases, and a cheap appliance for softening adhesive.
The indictment also describes a future rule working as a shipping deadline. In January 2025, prosecutors allege, Liaw sent a contact a White House release announcing "a new export rule involving artificial intelligence-related products, which was scheduled to take effect on or about May 13, 2025," and wrote: "We need to speed these up before May 13!" Days later, on pending orders: "We can ship all your 512 x B200 by Feb. Let us run fast before May 13!"
I will not name that rule, because the indictment does not. Several outlets filled in the blank; the point stands either way, which is that a public deadline worked as a scheduling input rather than a deterrent. And in August 2025, when a broker sent Liaw a Justice Department release about others arrested for smuggling AI chips to China, Liaw allegedly responded with sobbing emojis.
The market treated the allegations as information. Super Micro's shares fell 33% on Friday, March 20, 2026, according to CNBC — whose own key-points box says about 30%, so call it roughly a third. The company called the alleged conduct "a contravention of the Company's policies and compliance controls."
Not the only pipeline the government says it found
In a separate December 2025 action, co-conspirators allegedly removed Nvidia labels and re-labeled the GPUs with the name "SANDKYAN" — a fake company — with paperwork calling them generic computer parts. That case concerned at least $160 million of export-controlled H100 and H200 GPUs. It also holds the single conviction in this whole landscape: Alan Hao Hsu and his company, Hao Global LLC, pleaded guilty to smuggling and unlawful export activities on Oct. 10, 2025. Everyone else you read about here is a defendant, not a felon.
Senator Elizabeth Warren wrote to Nvidia's general counsel and audit committee chair on June 1, 2026, arguing these actions undermine CEO Jensen Huang's claim that there is "no evidence of any AI chip diversion". Note which figure she reaches for: $510 million, not $2.5 billion. When a senator hunting for leverage uses the smaller number, that is the defensible one.
The transit jurisdiction with nothing to charge
Then there is Taiwan, where this stops being an enforcement story and becomes a structural one.
In July 2026, Taiwanese prosecutors detained an Nvidia employee, bringing the number held in the probe to seven people, including two from Super Micro and one from Taiwan-listed Albatron Technology. The detainee is suspected of "the falsification of business documents under the Criminal Code," and the suspects are accused of forging documents to ship roughly 50 servers made by Super Micro to China. Nvidia has not been accused of wrongdoing, and Taiwan's authorities have accused no company of any.
Read the charge again. Falsification of business documents. Not unlawful export.
That is not prosecutorial squeamishness. Taiwan doesn't consider unauthorized AI chip exports to China to be a crime, Bloomberg has reported: authorities warn sellers they may be breaking US rules, but "the only legal recourse through the island's courts is to charge suspected smugglers with violations of other, existing local laws." Taipei is reportedly weighing controls that "would enable Taiwan to prosecute AI chip smuggling to China as a criminal violation for the first time." It cannot today.
Be precise, because this inflates in the retelling: shipping chips to China is not affirmatively legal in Taiwan. The criminal code reaches the paperwork, not the export. The lie is chargeable. The movement is not.
And Taiwan's control list, as Tom's Hardware explains, works off buyer names and carries no performance threshold — Huawei and SMIC were among 601 entities added in June 2025 — "so a rack of accelerators sold to a company that isn't on it needs no approval." A control keyed to who is buying rather than what is moving is defeated by a new corporate registration in an afternoon.
The regulator has quietly conceded the shape of the problem. Guidance from Commerce's Bureau of Industry and Security on May 31, 2026 clarified that a license is required to export advanced computing items to entities headquartered in certain country groups, or whose ultimate parent is — "even if the entities themselves are located outside Country Group D:5 or Macau". A clarification, not a new restriction, and not a response to this case: the requirement "was first introduced on November 17, 2023." But look at what it does. It makes the control follow corporate identity rather than destination — because destination stopped working.
The vendor reached the same conclusion. In July 2026 the Financial Times reported — per Reuters, which "could not immediately verify the report" — that Nvidia has more than halved the number of Asian customers authorized to buy its AI chips, after introducing a compliance "white list." When a company polices its own order book, it has stopped trusting the border.
So the controls have failed? Here is the strongest case that they haven't
I want to take the other side seriously, partly because it is good and partly because I notice how badly I want the collapse story to be true.
The best version comes from the Council on Foreign Relations, where Chris McGuire argues Huawei's constrained position is not a reason to loosen anything — it is "evidence that the controls are working". On CFR's numbers the best US AI chips are about five times more powerful than the best Chinese ones by total processing performance, and the piece projects Nvidia's best will be "seventeen times more powerful" by the second half of 2027 — a forecast in a regulatory metric, not a measurement of capability. It appeared on December 15, 2025, three months before the indictment, so it does not respond to this case. It is still the argument I have to beat.
A sharper point sits in the same analysis: citing SemiAnalysis, CFR reports Huawei could make 1.5 million AI chip dies in 2025 but finish only 200,000 to 300,000 chips, for want of high-bandwidth memory — export controlled in December 2024. The chokepoint actually biting may not be the one anybody is shouting about.
Then the numbers. Epoch AI models between 290,000 and 1.6 million H100-equivalents smuggled to China through 2025, median about 660,000 — "roughly a third of China's total compute." A model, not a count, and Epoch says so, flagging uncertainty about "the magnitude of undetected smuggling."
Here is why I trust the work: the same research cuts the other way just as hard. That median also represents roughly 3% of the global compute stockpile, "comparable to what xAI, a leading US AI lab, had at the time," while documented diversion evidence points to nearly 300,000 H100-equivalents — "roughly a quarter of the compute China acquired through legal channels or domestic production." Most of China's compute did not come through a shell company. Leakage at that scale is serious. It is not a collapsed policy.
And now the reframe most commentary missed. On January 13, 2026 — while this indictment was being drafted — BIS revised its licensing policy and announced it would review export license applications for the Nvidia H200 and similar chips case-by-case, provided certain security requirements are met. Some of the conduct described in the indictment involves exactly that class of hardware. Washington was, in part, legalizing a version of what it was simultaneously charging. Only in part: Blackwell-class hardware sits outside that pathway, and the indictment alleges orders for "512 x B200."
So the controls are neither a wall nor a fiction. What are they?
They are a control on the wrong kind of object — and I can show you that, because there is a second chokepoint in this same industry, run by allies, on the same theory of the case, and it has held.
The chokepoint that has held: roughly 340 machines, all of them accounted for
Cross to a town in the southern Netherlands and you find the mirror image of everything above.
Dutch law makes it an offense to export advanced semiconductor manufacturing equipment from the Netherlands without a license from the Minister. That is the whole mechanism, in one sentence — my translation of a text in force since September 1, 2023. It is a national layer bolted onto the European system, covering equipment not already named in Annex I of EU dual-use Regulation 2021/821. (I am quoting the consolidated version in force from late November 2025; the regulation has been amended.)
Before anyone reaches for the obvious explanation: the Dutch paperwork is not stronger. A Dutch application must state the destination "including the final destination," plus the name and address of the recipient and end user, and the license is revocable if granted on incorrect data. Same question my customs form asked — and the same one the American system asked the defendants here, which the government says they answered falsely.
The difference is not documentary. It is mechanical. It is about what happens to the object after it ships.
The Dutch expanded the measure from September 7, 2024 — their own ministry later told Reuters September 6, so note the discrepancy and move on — and tightened it again from April 1, 2025, because "the security risks associated with the uncontrolled export of these technologies have increased." Three ratchets in under two years. And note how they describe it: applications assessed case by case, "so this is not an export ban." Not a wall. A gate with a person at it.
ASML confirms the arrangement in its own releases: it must apply for export licenses with the Dutch government for its most advanced immersion systems, and the government decides. Since September 2024 the license for its TWINSCAN NXT:1970i and 1980i systems comes from The Hague rather than Washington, and sales of its extreme ultraviolet systems "are also subject to license requirements." Not "always were" — the 2023 statement says only that EUV sales "have already been restricted," and I will not smooth that into a cleaner story than the documents support.
You cannot put this in an unmarked box
An EUV lithography machine weighs about 180 tons, is roughly the size of a school bus, is built in limited quantities, and requires constant upkeep from the manufacturer's engineers. Back in 2022, CNBC reported each one is assembled from hundreds of thousands of components from nearly 800 suppliers, then disassembled for shipment — a process needing 20 trucks and three fully loaded Boeing 747s. Four-year-old figures, which I date deliberately, but the physics has not softened. Chris Miller, the historian who wrote Chip War and was an assistant professor at Tufts when he said it, called these systems "among the most complicated devices ever made."
Now put that beside the hair dryer. A server fits in a box, a box fits on a pallet, a pallet fits in a container, and a container is indistinguishable from ten thousand others. There is no version of that story involving three 747s.
The scale point becomes a counting point. Under US pressure in 2026, ASML circulated a presentation which — reviewed by Bloomberg, reported by the trade outlet implicator.ai — accounted for 314 EUV machines in operation worldwide and 26 decommissioned, none in China. ASML also claimed it can automatically detect "any interruption, abnormal behavior, or loss of connectivity" across the fleet, and that customers "cannot remove, transport and relocate EUV systems without ASML involvement." Attribute it honestly — a company's account of itself, reviewed by a news organization, reported by a third outlet — and it still does what no server statistic can: the entire global population of the controlled object fits on one page.
ASML has separately circulated a document in Washington titled "No indication of any ASML EUV system in China," stating it has "never shipped an EUV machine to China", nor any component specially designed for one. The company's own assertion, made under pressure — but note what it can even attempt: a claim of zero, verifiable in principle by counting.
Nobody can make that claim about GPUs. Nobody ever will.
The lever the server regime does not have
Size is half of it. The other half is that ASML never really leaves.
The company runs around 10,000 customer support employees round the clock, because a machine that is down "can cost customers thousands of euros per minute." Not charity — a quarter of the business: of €32.7 billion in 2025 net sales, €8.2 billion came from net service and field options. The machine is a subscription wearing the costume of a purchase.
So the most important sentence in this comparison is a Dutch clarification rather than a prohibition: ASML needs a license to provide "spare parts and software updates" for restricted equipment it has already sold to Chinese customers. Servicing, the ministry said, "is vetted under the licensing requirement (and includes)...parts, software and technology developed specially for this equipment."
The control does not end when the crate is opened. That is what the server regime cannot replicate — not because its drafters were less clever, but because a server, once delivered, does not need anybody.
Now four correctives, because a contrast section that only flatters one side is decoration.
One: the servicing lever is softer than it sounds. A pseudonymous industry analyst writing for ChinaTalk notes that ASML's immersion scanners "can often run for months at a time without maintenance," and that "the Dutch issue licenses only for physical goods, not technical services, so there is technically no expiration date on equipment servicing." That sits in direct tension with the ministry, and I will not resolve it for you — Reuters also reported the ministry was not planning further restrictions, so this is not an escalation story.
Two: Washington thinks the lever is incomplete. The MATCH Act, which passed the House Foreign Affairs Committee on April 22, 2026, would require the Netherlands and Japan to align their equipment restrictions with American rules within 150 days, cut off immersion lithography sales to named Chinese fabs, and ban the servicing of machines already installed there. A bill, not a law. But its stated logic could be this article's thesis: controlling equipment beats controlling chips because "a lithography machine is a $200 million tool that requires years of servicing by the manufacturer, while a chip is a commodity that can be rerouted through intermediaries."
Three: the strong chokepoint is under an allegation of its own — with less public support than the indictment, not more. Commerce Secretary Howard Lutnick told ASML's leadership in 2026 that one of its most advanced machines may have reached China, per Bloomberg; ASML denies it, and US officials declined repeated requests to produce evidence. I treat that more cautiously than the charged case, not less.
Four, and most important: the lithography chokepoint was routed around too — just differently. China did not smuggle a scanner; it changed technique. As the International Center for Law & Economics summarizes, Chinese manufacturers produced 7nm chips using older deep ultraviolet lithography and multi-patterning. Quoting Gregory Allen: "SMIC was already producing and selling 7 nm chips no later than July 2022 and potentially as early as July 2021, despite having no EUV machines."
There is even an explanation that has nothing to do with enforcement. Tom's Hardware assesses that China's reported reverse-engineered "Frankenstein" EUV prototype hasn't even produced a single chip, and notes ASML's tools run on proprietary software and firmware that are not public, so obtaining the hardware "does not guarantee that it functions as intended." A signed analysis of a reported prototype, not a confirmed one — hold it loosely.
But hold onto the mechanism, because it is what Nvidia claims about its own products. An Nvidia spokesperson told Tom's Hardware that "smuggling is a nonstarter" and that "any diverted products would have no service, support, or updates." A company statement, not a finding — and nothing I have read establishes whether a diverted GPU works without vendor support. ASML can demonstrate the dependency in its revenue line. Nvidia asserts it. The gap between those two is roughly the size of this article.
Just imagine the next three years
Let me get speculative — and label it as speculation, because the next move is already visible in the legislative record.
Just imagine it is 2029. The border never got better at seeing inside boxes, so the object was made to confess instead. Every covered accelerator ships with a location attestation module. Racks check in. A cluster declared to a warehouse in one country that answers from a facility 3,000 kilometers away trips a flag, and a compliance officer gets a ticket rather than a subpoena. Export control stops being a customs function and becomes a telemetry function.
Now the second-order effects, because this is where I stop cheering. A chip that reports its location is a chip somebody can switch off, and the distance between "location verification" and "remote disablement" is a firmware update and a bad afternoon in a trade war. Countries with no quarrel with anyone start asking why their national AI capacity phones a foreign capital — and some build their own stack, badly and permanently. The control succeeds and fragments the thing it was protecting.
Or imagine the other branch, where attestation never ships and the control migrates to the relationship instead: approved-buyer lists, mandatory servicing contracts, cloud-only access to the top tier so the object never leaves anybody's building. Compute becomes something you rent from a jurisdiction rather than own in a rack — the ASML model applied to silicon. I do not know which branch we get. I am confident we do not keep this one, where the architecture depends on a distributor in a third country writing the truth on a form.
What the people who do this for a living are arguing about
This fight does not split along the usual lines. It splits along a question about objects.
Start with resourcing, the least ideological point available. At the Center for Strategic and International Studies, Gregory C. Allen laid out the mismatch: as of his October 2024 accounting, the Bureau of Industry and Security had fewer than 600 employees and "a relatively paltry budget of just under $200 million" to oversee trillions of dollars of activity and police smuggling worldwide. BIS has requested more since. Even so: the agency asked to hold this chokepoint is smaller than a mid-sized company.
From the hawkish side, Jack Burnham of the Foundation for Defense of Democracies, writing in CyberScoop in April 2026, offers his own uncited figure — treat it as his: federal spending on policing export controls amounted to $122 million in all of 2025. His prescription is to move enforcement upstream, "at the factory floor rather than the airport gate," because US export law is built to stop things leaving the country and does not stop Chinese firms buying them inside it.
From the tech-industry side — and the Information Technology and Innovation Foundation does take industry funding, which you should know — the argument is that the apparatus is self-defeating: policy churn and uncertainty "undermine American firms that follow the rules, limit their ability to compete globally, and push international customers toward Chinese suppliers."
And from the market-liberal side comes the observation that convinced me this thesis is not partisan: the International Center for Law & Economics notes that some skeptics of chip export controls simultaneously support strengthening controls on the equipment needed to make chips — the analyst Ben Thompson's position being exactly that. This article's argument, reached from the free-market direction.
The academics go further. A 2024 preprint by Ritwik Gupta and colleagues — Leah Walker and Andrew W. Reddie — titled Whack-a-Chip: The Futility of Hardware-Centric Export Controls argues that Tencent's ability to power its Hunyuan-Large model with non-export-controlled H20s exemplifies efficiency gains that have eroded the moat that the United States initially built. A preprint, not a peer-reviewed study, and its evidence is pre-Blackwell hardware from November 2024, so do not stretch it to today's frontier training. The core claim survives anyway: even a perfectly enforced hardware control chases a target software keeps moving.
Congress has picked the technical answer. The Chip Security Act, introduced as H.R. 3447, would require Commerce within 180 days of enactment to mandate chip security mechanisms that implement location verification on covered chips before export. It passed the House Foreign Affairs Committee on March 26, 2026 — seven days after the indictment was unsealed. Several write-ups attach a unanimous vote count to that; no primary source I can reach supports one, so I am not repeating it. It passed committee. It is not law.
Is location verification feasible? Analysts at AI Frontiers conclude it is — Nvidia has acknowledged that transmitting "limited telemetry—including information on location and system configuration" would be technically feasible to develop. Their verdict on what it buys you is the line I would tape to a congressional whiteboard: location verification "isn't a silver bullet."
Feasible is not deployed. Deployed is not enforced.
What does this mean for you?
You will not license a lithography machine this year. But this story is a masterclass in reading the next twenty policy fights.
Spot the two-number switch. When a story hands you one enormous figure, ask which it is: what was sold, what is alleged to have moved, or what has been proven. Here that is $2.5 billion, $510 million, and zero dollars adjudicated. A piece that uses them interchangeably is not reporting, it is atmosphere.
Read the charging document, not the coverage. It took me twenty minutes to find this indictment on a public docket, and the government's text is more careful than most of what was written about it.
Take DOJ at its word about its own press releases. It instructs that every fact be treated as an allegation. Extend that to companies and defendants you dislike — it is the only version of the rule worth anything.
If you work near procurement or logistics, check your end-user verification. The alleged failure point was not a border. It was a distributor's declaration about who was receiving the goods. Ask who has confirmed where your last shipment ended up.
Ask the mechanism question about any control proposed to you. Not "is it strict?" but: what happens to the object after it ships? If the answer is "nothing," the control is a document. If it is "it stops working without the seller," you have teeth.
Refuse both triumphalism and doom. The same Epoch AI research shows diversion at roughly a third of China's compute and roughly 3% of the world's. Anyone quoting one number and not the other is selling you a conclusion.
The lesson, as I read it
Export controls are not a wall. They are a bet about the physical properties of a thing.
Where the bet is well placed — the object weighs 180 tons, exists in the low hundreds, and stops working without the vendor's engineers — the control does roughly what it promises, for years, and can be audited by counting. Where it is badly placed — the object is small, fungible, rack-mountable, and fully functional the moment the pallet is unwrapped — the control becomes a declaration on a form, enforced by an agency of a few hundred people, in a transit jurisdiction that may not even have an offense to charge.
That is not a failure of American resolve. If anything Washington has been serious in the way that produces indictments rather than results. It is a mismatch between an instrument and an object. You cannot legislate a server into being a school bus.
So the honest options are narrow and all uncomfortable. Change the object, and a chip that reports its location is a chip somebody else can switch off. Change the leverage, and compute gets rented from a jurisdiction rather than owned in a building. Or keep this arrangement, fund it properly for once, and tell the public plainly that it leaks.
What I cannot accept is the fourth option, the one we are running: a policy that assumes a chokepoint, a budget that cannot staff one, and a press cycle that reports every indictment as either vindication or collapse.
I got my customs form wrong out of tiredness, and the system believed me because believing me was cheaper than checking. Scale that by nine zeros and you have the national security policy of the largest economy on earth.
One chokepoint weighs 180 tons and cannot be moved without its manufacturer in the room. The other one, prosecutors say, met a hair dryer.






