The export-control arc: October 2022 to the Diffusion Rule and back
Lesson 2 of 5 in Compute Governance, Export Controls, and the Science of AI Safety.
On 7 October 2022, the US Bureau of Industry and Security (BIS) published the most consequential AI policy document nobody in AI governance was reading at the time. It restricted exports to China of advanced AI accelerators (the A100 and H100 class), the equipment to make advanced chips, and — a genuine novelty — barred US persons from supporting advanced Chinese fabs without a license. The stated theory: China’s military-civil fusion doctrine means advanced compute anywhere in China is advanced compute available to the PLA, so the US would no longer aim to keep a relative lead but to impose an absolute ceiling.
What followed is the best case study in existence of how technology controls and technology firms co-evolve. Treat each round below as a move in a game, and notice who moves next.
Round 1 — October 2022: the performance thresholds
BIS drew the line with two technical parameters — chip-to-chip interconnect bandwidth and total processing performance. NVIDIA’s response arrived within weeks: the A800 and H800, chips engineered to sit just under the interconnect threshold while keeping most of the training performance. Entirely legal, openly sold, and a masterclass in why parameter-based controls invite parameter-targeted engineering.
Round 2 — October 2023: closing the loophole, adding density
BIS rewrote the rules to catch the A800/H800, replaced the interconnect test with total processing performance and performance density metrics, added a gray-zone notification tier, and extended controls to dozens of countries seen as transshipment risks. NVIDIA responded again: the H20, a China-market chip under the new lines — weaker for training but genuinely strong for inference. The cat-and-mouse pattern was now structural.
Round 3 — December 2024: HBM and the toolmakers
The third round targeted high-bandwidth memory — the component modern accelerators are starved without — plus additional semiconductor-manufacturing equipment and some 140 entity-list additions. The logic had shifted visibly upstream: if chips leak, control the ingredients of chips.
Round 4 — January 2025: the AI Diffusion Rule
In its final week, the Biden administration published the Framework for Artificial Intelligence Diffusion — the most ambitious compute regulation ever attempted. It sorted the world into three tiers: ~18 close allies with near-unrestricted access; a broad middle tier subject to country-level compute caps and validated-end-user licensing; and arms-embargoed states (China, Russia, and others) essentially excluded. For the first time it also controlled the export of certain closed model weights — treating the trained model itself, above roughly 10²⁶ FLOPs of training compute, as a controlled item.
Round 5 — May 2025: rescission and improvisation
Days before its compliance date, the Trump administration rescinded the Diffusion Rule, calling the tiering unworkable and insulting to middle-tier partners, and promised a replacement built on bilateral deals. What followed instead was policy by episode: guidance warning that using Huawei Ascend chips could violate US export law; an April 2025 license requirement that halted NVIDIA H20 sales to China (a multi-billion-dollar write-down); then a mid-2025 reversal reportedly permitting H20 sales in exchange for a share of China revenue paid to the US government — an arrangement with no clear precedent in export-control law.
Did the controls work? The honest expert answer is partially, and the counterfactual is unknowable. Chinese labs kept shipping competitive models — DeepSeek’s R1, released in January 2025 and trained (per its developers) far more cheaply than US frontier runs, detonated the assumption that compute restrictions had frozen Chinese progress. Skeptics read DeepSeek as proof the controls failed; defenders noted it was trained on stockpiled and China-market NVIDIA chips acquired before and around the rules tightened, and that the constraint bites hardest on the next order of magnitude of scale. Both can be true.
Meanwhile enforcement became its own field: DOJ smuggling prosecutions, Singapore-routed diversion cases, and a persistent gray market in rented offshore compute. The lesson for governance professionals is not "controls are futile" — it is that a control regime is a system with a maintenance cost, and the gap between rule text and shipped silicon is where your compliance work lives.
The frontier-policy years
- 2022-10-07 — US advanced-chip export controls on China:
Sweeping controls on advanced semiconductors and manufacturing equipment — compute becomes an explicit instrument of AI policy.
- 2023-10-17 — US tightens chip export controls:
The 2022 rules are extended to close performance-density loopholes and cover more countries — the compute-control net widens.
- 2025-01-13 — AI Diffusion Rule issued — then rescinded:
A three-tier global framework for AI chip and model-weight exports, issued in the administration’s final week and rescinded by its successor in May 2025 — export policy whiplash.
- 2025-02-01 — Frontier safety frameworks become table stakes:
Following the Seoul commitments, major labs publish or update frontier safety policies (capability thresholds, evaluation gates, deployment mitigations) ahead of the Paris summit.
- 2026-06-01 — EO 14409 on frontier-model cybersecurity:
Federal attention narrows to security of frontier models — weights, infrastructure, adversarial threats. Check current status for implementing rules.
Tool: Regulatory Time Machine — Replay 2022–2026 in the Time Machine and watch each export-control round land against the model releases it was reacting to.
Interactive checkpoint quiz (3 questions) — open this page in a browser to take it.