Exporting American AI to Create Jobs, Grow Our Economy, and Beat China
Key Takeaways
« America must seek to export its AI technology abroad. Doing so will help to reshore American manufacturing and jobs, drive economic growth, counter the PRC’s influence, improve national security, and make U.S. AI the global default.
« The Trump Administration has created two programs to export and secure AI: the American AI Exports Program and Pax Silica. These will finance strategic projects across the AI stack.
« We recommend ways to improve these programs through changes to funding and incentives, new provisions to protect American business, and new security guarantees. With these changes, the U.S. can more effectively export American AI to create jobs, grow our economy, and beat China.
Introduction
America must export its world-leading AI stack abroad. Promoting the export of American AI technology is one of three pillars in the White House’s AI Action Plan and, as President Trump said, we must “turn America into an AI export powerhouse” (Kratsios et al., 2025). Doing so will create American jobs, grow the economy, and reshore manufacturing.
The history of international technology competition shows that the companies and countries with the largest ecosystem for developers and users win, including in open source. America must also export AI to counter the People’s Republic of China (PRC)’s hard and soft international power. The PRC seeks to push its values and economic system onto unaligned third countries through financing and technology exports, which the U.S. can disrupt by exporting its own superior products.
In doing so, however, the U.S. must ensure that it does not inadvertently aid its adversaries by allowing chipmaking equipment, semiconductors, or cloud computing resources to be diverted. The U.S. can prevent this by establishing rigorous and consistent security rules for exports. Finally, as American technology diffuses abroad, so too will our usage and development standards, which will determine the values and victors of the future. As U.S. AI becomes the global default, and we ensure that AI products and hardware are developed in America by American workers, we can create growth that boosts employment and national strength.
In 2025, the U.S. government created two landmark programs to achieve these goals while promoting and protecting U.S. AI exports: the American AI Exports Program and the Pax Silica economic security agreements (Trump, 2025; Department of State, n.d.). This issue brief describes how these programs can succeed as they enter the implementation phase and deploy capital. They need more funding and incentives for participation, more provisions that protect American business, and stronger security guarantees to prevent adversaries from accessing or tampering with our technology.
By implementing a vigorous strategy to improve and expand these programs, the U.S. can secure its economic and national security interests while ensuring robust American employment. This report lays out such a strategy to equip policymakers for the opportunity of the moment.
What is the American AI Exports Program?
President Trump established the American AI Exports Program by Executive Order in July 2025 (Trump, 2025). The Program, headed by the Department of Commerce, aims to promote “full-stack AI export packages.” The “stack” of AI includes energy infrastructure, data centers, chips, data, models, and applications. Companies are asked to form “consortia” to create these packages, which would include data center hardware, data pipelines, AI models and systems, security and cybersecurity measures, and AI applications.
These consortia will then receive financial, diplomatic, and other support mechanisms from the government. The Economic Diplomacy Action Group (EDAG) will coordinate financing for the program through various organizations, including the U.S. Export-Import Bank (EXIM), International Development Finance Corporation (DFC), and Trade and Development Agency (TDA). Diplomatic and other support mechanisms may include dissuading burdensome foreign regulation, incentivizing countries to adopt these packages, and approving the export of advanced AI technology under certain conditions.
The Department of Commerce’s International Trade Administration (ITA) opened a call for proposals on April 1, 2026 (Kimmitt, 2026). It considered proposals in its first iteration on a rolling basis until June 30 and issues consortia designations under the program within 60 days of submission.
Why is Exporting American AI So Important?
The American AI Exports Program is a central pillar of the Trump Administration’s AI policy and perhaps its most innovative piece. It is the first government AI program that understands the crucial importance of foreign market dominance—something the private sector has long known.
Indeed, American companies in the AI supply chain understand the importance of capturing global markets. Consider semiconductors as an example. In 2024, U.S. demand was only 19.2% of global demand (Market.us, 2025). Yet American companies hold 50.4% of global market share and make about three-quarters of their sales abroad by revenue (SIA, 2025; ATREG, 2024). U.S. companies have held a dominant position in the global semiconductor market since 1997 (SIA, 2025).
Figure 1
U.S. Share of Global Semiconductor Consumption Versus Sales

Note. American semiconductor companies heavily export their products. The U.S. produces a far larger share of the world’s semiconductors than it consumes. Data from Semiconductor Industry Association, 2025 Factbook, 2025, and Market.us, Semiconductor Market Report, 2025.
With the American AI Exports Program, the Trump Administration is the first to recognize that the federal government has an important role to play in America’s global AI dominance. The U.S. government is now in a position to leverage its market dominance to ensure its global economic and security interests are best accommodated. This will become more apparent as AI’s importance increases and many nations seek to develop AI prowess—both for their national security and to avoid falling behind in an economic “great divergence” (Helberg et al., 2026).
The full-stack export of American AI is a critical priority for several reasons.
(1) The country with the largest ecosystem will win. Companies and countries whose technology is used by the most developers, integrated with the most software, designed for the most languages, and so on will win the AI race. Consider the commercial moat that chip designer Nvidia has created. It has done so not only by developing the best chips, but also by linking them to proprietary software, called CUDA, that is preferred by researchers, universities, applications, and especially AI developers (Markman, 2026). Building a hardware, software, and talent ecosystem around U.S. AI will make it the global default and create a technology moat. As a result, network effects and self-reinforcing adoption benefits will allow U.S. companies to capture the majority of global market share across the AI stack.
On the other hand, should the PRC develop competitive technology across the AI stack or in parts of it, such as models, it could create moats that prevent American companies from competing. In 2025, for example, Africa’s largest smartphone company, Transsion, integrated Chinese models from DeepSeek and Alibaba into its phones by default (Infinix, 2025; Cao, 2025). As a result, over 40% of smartphone users in Africa default to using Chinese AI models, presenting a serious setback to the U.S.’s AI export interests.
(2) Export promotes open source. Open source technology is the ultimate ecosystem amplifier. It is often said that “the internet is built on open source software”; indeed, one estimate suggests that “96% of all software” relies on open source (Choudhury et al., 2023). But open source tooling itself is often built to rely on proprietary tools. The popular open source AI agent framework LangChain, for example, is built around and defaults to developer tools like the OpenAI Application Programming Interface (API) (Israelsen, 2024). Similarly, the most popular machine learning programming library, PyTorch, is also built on top of Nvidia’s proprietary CUDA software (Patel, 2023).
Because tools like LangChain and PyTorch are so ubiquitous in AI, developers and customers have even more reason to default to American companies—like OpenAI and Nvidia—for the full stack. This self-reinforcing loop between open source and proprietary technology is what creates and hardens large ecosystems. By exporting its full AI stack at the start of the AI revolution, America can use this loop to cement global usage of our technology.
(3) Export creates American jobs and grows our economy. The benefits of the AI boom for American workers and the economy are well documented (Mahmood et al., 2026). Its impact is large and positive for both wages and GDP. It is a “gold rush” for construction workers and has already doubled the share of US GDP from computing infrastructure relative to 2023 (to 1.5%) (Chen, 2025; Juniewicz, 2026). By entering foreign markets, establishing American AI as the global standard, and winning market share for American companies across the entire AI stack, U.S. companies will manufacture more chips, employ more engineers, build more data centers, and finance more energy infrastructure. Promoting American AI exports will help reindustrialize and reshore the United States, both of which are necessary for our economy and national security.
(4) Exporting American AI counters the PRC’s influence. The PRC seeks to win hard and soft power internationally by exporting its technology. This is the goal of its Digital Silk Road (DSR) initiative which, since 2015, has sought to “create an illiberal political international order” by investing in high-tech industries abroad (Cheney, 2019). These development financing projects are part of the larger Belt and Road Initiative, which spent over $1 trillion between 2013 and 2023 (McBride et al., 2023). The PRC also uses its embassies to facilitate investment, standards, and adoption of its technology abroad. One study found that over 10% of Chinese embassy announcements in 2025 were related to “AI cooperation,” up from 2% in 2022 (Wang et al., 2026). The PRC uses these economic relationships to build soft power, export authoritarianism, and enhance its national security (Cheney, 2019).
But these initiatives depend on the PRC’s ability to offer attractive AI products. If foreign markets adopt the American AI stack—whether due to moats or because our products are superior—the PRC’s influence will likely diminish. Beijing’s attempt to leverage AI to support its global authoritarian and anti-American designs will fail. In turn, we can promote American values and enhance security across the globe.
(5) Government-backed exports have stronger security. Exporting American AI is designed to counter the PRC’s influence. It is therefore paramount that our exports do not benefit Chinese companies or their AI development. The White House’s AI Action Plan recommends that, under the AI Exports Program, the Department of Commerce “facilitate deals that meet U.S.-approved security requirements and standards” (Kratsios et al., 2025). Exporting AI in concert with the private sector will allow the U.S. Government to place and enforce such requirements and standards. The Secretary of Commerce, for example, could require the use of location verification technology on high-end chips exported through the Program to ensure they are not physically diverted to the PRC or other countries of concern. By incentivizing private participation in the Program, the administration can now ensure that AI products are exported securely, even when sent to countries with limited domestic oversight.
(6) America can export its standards with its technology stack. Usage and adoption standards shape which products are preferred globally. This applies throughout the AI stack. Consider the historical case of cellular communication standards. At the turn of the century, the European cellular standard (GSM) was competing with the U.S. standard (CDMA) for dominance. Although CDMA “offered a better technical product,” GSM eventually won out because it convinced more companies to rely on its standard, achieving over 90% market share by 2014 (S&P Global, 2006; 4G Americas, 2014). Its success cascaded throughout infrastructure, cell phones, and software.
In a similar way, American AI export packages backed by the government will bring standards with them. Nvidia’s CUDA, the open source PyTorch, and the AI agent standard Model Context Protocol (MCP) are all standards that, when exported, help American companies win (Google Cloud, n.d.). America can also promote open usage standards that discourage the PRC’s authoritarian influence—exemplified by Chinese models that refuse to discuss human rights in the country (OpenAI, 2026). For example, Chinese models often refuse to discuss Tiananmen Square or Taiwanese independence.
Pax Silica and Supply Chain Security in Exports
The AI supply chain is among the most complex in the global economy. The “AI stack” includes not only foundation models and the data centers used to train and run them, but also the critical minerals needed to produce chips, the energy infrastructure that powers data centers, the shipping routes that bring chips to their final destinations, and diverse other essential inputs. In such a multilayered supply chain, there are many potential bottlenecks that adversarial regimes could leverage or even weaponize against the U.S. and our allies.
The most prominent recent example has been the PRC’s stranglehold on the mining and refining of some critical minerals for AI chips, magnets, batteries, and other layers of the AI buildout. On September 29, 2025, the Trump Administration closed a loophole in controls on exports of AI chips and the equipment needed to manufacture them to the PRC (Reuters, 2025a). The order extended those controls to the foreign subsidiaries of blacklisted Chinese firms, preventing the firms from evading American export controls by working through such subsidiaries. Ten days later, Beijing retaliated by threatening to assert control over any product made anywhere in the world that contained Chinese-origin rare earths or used Chinese refining technology (Baskaran, 2025). Given the PRC’s near-monopoly in these industries, the proposed rule would have given Beijing an effective veto on any Western AI chip manufacturing or American AI data center construction. Markets panicked in response, and Washington suspended the subsidiary-blacklisting rule for a year (Khersonsky, 2025).
If the PRC can credibly threaten to shut down American chip manufacturing and data center construction, and even use those threats to change American policy, then the US faces serious AI sovereignty vulnerabilities. Chinese control over any bottleneck in the AI supply chain therefore represents a clear threat to American AI supremacy.
Two months after the PRC threatened to institute global controls on the AI supply chain, the State Department launched Pax Silica (U.S. Mission China, 2025). This initiative aims to deny American adversaries the opportunity to weaponize bottlenecks in the AI supply chain by working with allies to expand alternative “trusted” sources of critical minerals and other essential inputs. The primary mission is to “reduce coercive dependencies,” so authoritarian adversaries cannot continue to use threats to limit or even dictate American and allied AI policy (Department of State, n.d.).
The American AI Exports Program relies on partners understanding that the American AI stack is reliable, so Pax Silica’s mission to secure the AI supply chain is an essential component of the campaign. More than 20 American allies, including India, South Korea, the UAE, the U.K., Japan, and the Philippines, have joined the initiative by signing the Pax Silica Declaration, which affirms the importance of reliable AI supply chains (Department of State, n.d.). Taiwan has also joined as a non-signatory participant. Each of these nations is essential to the operation of the AI supply chain, from critical minerals to energy to data center infrastructure. The Pax Silica initiative represents a promising opportunity for the U.S. to lead a global push to secure the AI supply chain from interference by authoritarian adversaries.
In March 2026, the Department of State announced that it intends to seek $250 million in “foreign assistance funding for a new Pax Silica Fund initiative to support critical minerals extraction, processing, critical infrastructure, and manufacturing assets that support secure and reliable semiconductor supply chains” (Department of State, 2026).
Building an Exceptional AI Exports Program
The AI Exports Program must be implemented to benefit not only American companies but also our markets, national security, and people. In this section, we propose three categories of upgrades that would enhance the Program’s ability to maximally benefit America: (1) increasing its funding and incentives, (2) protecting American business, and (3) establishing security guarantees. These policies would accelerate international American AI dominance, grow and reshore the American AI supply chain, and prevent the PRC from stealing our most valuable technology.
1. The AI Exports Program Needs Funds and Incentives
Problem: The Program has limited funds. The Order establishing the Program specifies the use of three export development offices: the U.S. Export-Import Bank (EXIM), International Development Finance Corporation (DFC), and Trade and Development Agency (TDA).
- As of September 2025, EXIM has $100.2 billion in available lending (EXIM, 2025). This results from its current outstanding balance and statutory lending limit of $135 billion. This earmark represents total, not annual, lending.
- As of 2025, DFC has a $205 billion investment limit over six years (DFC, 2025).
- TDA is a small organization focused on export promotion through activities like feasibility studies and reverse trade missions. Its 2026 budget was $87 million (Akhtar, 2026).
These funding levels are large. Although they are far smaller than the $660–690 billion that America’s five largest AI infrastructure developers have committed to spending in 2026, these development offices are not designed to finance entire projects (Patience, 2026). DFC, for example, shares equity with private investors and typically funds less than 50% of a project (DFC, n.d.). Further, research finds that the causal impact of $1 of EXIM investment is $4.50 in increased U.S. exports (Matray et al., 2025).
But these funds are not AI-specific. EXIM’s chair, for example, said he plans to use its outstanding $100 billion lending balance for critical minerals, nuclear energy, and natural gas projects (Reuters, 2025b). EXIM has announced an “ExportAI Initiative” that seeks to deploy capital under the AI Exports Program, but it is unclear how much of its available lending will be dedicated to the Initiative (EXIM, 2026). DFC has a new, large investment limit, but it has never committed more than $12 billion in a year (Henagan, 2025). Its recent reauthorization has also asked it to focus on energy and critical minerals (DFC, 2025). Overall, the Program may fail to deliver global American ecosystem dominance if it does not receive carve-outs from EXIM, DFC, or other investment vehicles.
Solution: Carve out investment and lending sums for the Program. For the Program to incentivize large full-stack export agreements in foreign markets, it needs reliable stores of capital. It should not rush execution to draw funds from EXIM or DFC before other projects can saturate their lending/investment limits. Therefore, the President should direct EXIM and DFC to reserve as much as a quarter of their lending/investment limits for the AI Exports Program. Alternatively, Congress could mandate the same reservation. This would leave the Program with about $75 billion in deployable capital—more comparable to the huge sums expended on AI infrastructure. Plenty of the EXIM and DFC limits could still be expended on other important purposes, like energy and critical minerals supply chains.
Further, the Department of Commerce (DOC) could deploy investments secured by trade agreements to incentivize companies to participate in the Program. DOC has secured at least $750 billion in required foreign investments from Japan and South Korea (Memorandum of Understanding, 2025; Reuters, 2025c). These investments are structured such that the U.S. Government receives full equity in any project it wants the foreign nation to finance (and cash flows are split). In addition to EXIM and DFC direct investment or lending, DOC could arrange for companies that participate in the AI Exports Program to receive some equity in AI-related projects developed under Japanese or Korean investment, as appropriate. Many of these are expected to be data center or semiconductor projects (Kihara et al., 2026).
Problem: Exporters have few incentives to join the program and still face complex export rules. Although total available financing for the program could be increased, for now it remains low. In addition to financing, the primary incentives for exporters to join the Program are “priority export licensing” and “government advocacy” (Department of Commerce, n.d.). These incentives are not sufficient to encourage large American AI firms to create and fund consortia for strategic investments that promote U.S. export goals. The Biden Administration sought to solve this problem by creating the so-called “diffusion rule” (Bureau of Industry and Security, 2025a). But that rule too strongly dictated the distribution of exports and did not prioritize strategic investments. It also needlessly alienated many allies, such as Portugal, which were arbitrarily placed in lower “export tiers” than countries like the United Kingdom (Bureau of Industry and Security, 2025a). Fortunately, the Trump Administration declined to enforce the rule (Bureau of Industry and Security, 2025b).
Nevertheless, existing export controls on technology across the AI stack—including on semiconductor manufacturing equipment (SME), AI chips, and software—are convoluted and disincentivize strategic exports. The differences in export rules for chips and cloud infrastructure between the United Arab Emirates (UAE) and Malaysia are illustrative. The UAE is not a major export risk for transshipment or physical diversion risk to the PRC, insofar as it does not have the geographical or geopolitical ties to the PRC that create these risks. Nonetheless, firms seeking to export chips to the Gulf States face rigorous license reviews and ongoing scrutiny by the Department of Commerce to meet “rigorous security and reporting requirements,” though the Trump administration has recently taken away many of these requirements (Department of Commerce, 2025; Fountain, 2026). These requirements protect against physical and cloud diversion. Yet large shipments to Malaysia, which, as we will discuss later in this report, is a hub for chip diversion to the PRC, face almost no scrutiny. Most shipments to Malaysia, even of the highest-end chips, do not require export licenses at all (Shilov, 2026). This asymmetry between states is arbitrary and does not reflect the true levels of diversion risk by country. Instead, license reviews and security and reporting requirements should be initiated based on the scale of computing power being exported and the diversion risk of the country.
Solution: The Department of Commerce (DOC) should create a unified AI chip export licensing process linked to participation in the AI Exports Program. Since DOC rejected the diffusion rule in May 2025, it has sought to establish a more sensible, unified export license review framework. In March 2026, it was reported that DOC had developed such a framework, though it was eventually withdrawn (Eastland, 2026). The proposed “global chip export strategy” would reportedly have required DOC’s Bureau of Industry and Security (BIS) to grant export licenses for large AI chip shipments based on “a range of factors, including government-to-government agreements and how much computing power each end user was seeking” (Eastland, 2026).
Implementing a unified strategy similar to the scrapped BIS proposal, but narrower in scope, would remove arbitrary differences in how export rules are imposed (like those between the UAE and Malaysia). BIS would be able to tie the level of export review scrutiny to the level of physical and cloud diversion risk posed by export to particular customers or countries. The strategy could identify countries where physical and cloud diversion risk is high and require firms seeking to export to those countries to do so through full-stack consortia under the AI Exports Program. This would increase the anti-diversion security of these exports by linking them to full-stack products operated by American companies. It would also incentivize growth in American business across the AI stack by requiring chip exporters to find American partners for models and infrastructure. The strategy should also ensure the PRC, Russia, and other countries of concern cannot receive high-end American chips.
2. America Must Protect American Business
Problem: American business is threatened by foreign AI export initiatives. America’s market is the most important in the world. Prices at home determine the way of life for hard-working Americans. The success of domestic businesses creates jobs and prosperity. Further, domestic supply chains in AI are a national security imperative exemplified by the critical minerals crisis and military power of AI data centers (Creitz, 2026; U.S. Army, 2026).
But foreign competitors seek to displace American companies in American markets throughout the AI stack. The PRC’s open-weight AI models, for example, are highly capable and have been widely adopted by American companies. Researchers report that “Chinese-made open-weight models are now unavoidable” and “are increasingly being adopted in the U.S.” with as much as 30% penetration (Carroll, 2026; Aubakirova et al., 2025). Further down the technology stack, Taiwan’s near monopoly in AI semiconductor manufacturing is also troubling. Treasury Secretary Scott Bessent has called its 97% production share “the single biggest point of single failure” in the global economy (Mickle, 2026).
Solution 1: Congress should ban government agencies and government contractors from using Chinese-origin AI technology. In 2025, Congress banned the Department of War and its contractors from using AI models developed by the PRC’s DeepSeek (S.1071, 2025). It should broaden this ban. No government agency should be allowed to use Chinese-origin technology from the AI stack in its mundane operations. It should exempt usage for the purposes of assessment and intelligence operations, or if waived by a Department head with special, clearly necessary approval.
Solution 2: Congress should slow the PRC’s semiconductor indigenization by strengthening export controls on semiconductor manufacturing equipment. As the PRC builds an increasingly capable indigenous semiconductor supply chain, the scale and attractiveness of its chip exports grow. Today, the PRC’s capacity to produce AI chips is so small that exports trade sharply against domestic use (Reuters, 2025d). But PRC companies have spent years purchasing and stockpiling advanced American and allied semiconductor manufacturing equipment (SME) that has accelerated their progress. According to a 2025 report by the House Select Committee on the CCP, the PRC represented 39% of revenue in 2024 by the five largest SME producers (Select Committee on the CCP, 2025). A substantial share of this revenue came from currently export-restricted Chinese companies, including those that sell to the People’s Liberation Army (PLA).
For the United States to achieve maximum penetration in global markets, as the AI Exports Program seeks to achieve, we must prevent the PRC from developing competitive technology. Perhaps the single most impactful SME policy the US could implement is to ban the sale of deep ultraviolet immersion (DUVi) lithography systems to the PRC and other countries of concern. This technology, which uses baths of water to print small shapes on chips, is produced exclusively by Dutch and Japanese companies but has been used by the PRC to make its first 7 nm and 5 nm AI chips (Fedasiuk et al., 2026). In 2024, 70% of DUVi lithography sales by Dutch producer ASML, which holds a near-monopoly on the technology, were to the PRC (Select Committee on the CCP, 2025). As Chinese producers, like its national champion chipmaker Semiconductor Manufacturing International Corporation (SMIC), ramp up AI chip production using lithography and other SME from the U.S. and its allies, U.S. companies will find stiffer competition in global markets. To prevent this, Congress should ban export of DUVi lithography and most other cutting-edge SME to the PRC and other states of concern.
Figure 2
Share of Top Five Semiconductor Manufacturing Equipment Firm Sales to the PRC in 2024

Note. In 2024, the world’s five largest semiconductor manufacturing equipment (SME) firms received an average of 39% of all revenue from the PRC. In deep ultraviolet immersion (DUVi) lithography equipment, which is particularly crucial for building advanced node AI chips, 70% of revenue at the largest firm, ASML, was from the PRC. Data from House Select Committee on the CCP, Selling the Forges of the Future, 2025.
Solution 3: The Department of Commerce should work with allies, particularly the Netherlands and Japan, to ban critical SME sales to the PRC. Deep ultraviolet immersion (DUVi) lithography machines are almost exclusively produced in the Netherlands and Japan. These machines are used by the PRC to create cutting-edge AI chips while bypassing controls on more advanced lithography equipment (Fedasiuk et al., 2026). However, the Netherlands and Japan do not have export controls comprehensive enough to prevent the PRC from accessing DUVi. For example, ASML is now reportedly “reviving a discontinued tool, the NXT:1965i, to undermine Dutch restrictions” (Moolenaar, 2026). To fill all existing loopholes, the Department of Commerce should work with the Department of State and other offices to ban the sales of DUVi technology to any Chinese entity. This is the only way to mitigate diversion and prevent our allies from helping the PRC indigenize its semiconductor industry.
3. The AI Exports Program Needs Security Guarantees
The White House’s AI Action Plan says that AI Exports Program deals must “meet U.S.-approved security requirements and standards” (Kratsios et al., 2025). This stems from two concerns. First, our adversaries may seek to interfere with U.S. AI supply chains. Second, our adversaries may seek to divert AI computing capacity—physical chips or cloud capacity—that we export. As we begin to export American AI worldwide, we must prevent both by tying exports to rigorous security guarantees.
Problem: The AI Exports Program—and U.S. AI supply chains more broadly—may become targets of foreign interference. As discussed above, American adversaries have already used their control of certain critical minerals in the AI supply chain to threaten and gain diplomatic leverage over America and our allies. Because the AI supply chain is so complex, there are many potential bottlenecks or opportunities for sabotage that foreign adversaries could leverage for their authoritarian and anti-American ends. The most pressing bottleneck is currently the PRC’s control of rare earth mining and processing (Baskaran, 2025).
The Pax Silica initiative, introduced above, aims to overcome this challenge by working with American allies to reduce dependencies on adversaries in the AI supply chain. However, this goal will not be met easily. In some industries, building resilient alternative supply chains represents a multi-year undertaking that will require billions of dollars of investment. In the West, building a facility to mine critical minerals takes on average 14 years from initial investment to operation (IEA, 2021). It will be difficult for the State Department to persuade Pax Silica partner governments and private industry to support such long-term enterprises, especially when the existence of Chinese competition makes profits uncertain.
Solution: Congress should invest in the Pax Silica Fund and use it to incentivize partner governments and private companies to invest in alternative AI supply chains. The State Department claims that $250 million in funding will effectively support the Pax Silica initiative, particularly by motivating investments from private partners and sovereign wealth funds (Department of State, 2026). As the Department plans, this funding should not be used merely to subsidize infrastructure projects overseas. Instead, the Fund should catalyze private and foreign capital. In keeping with Secretary of State Rubio’s “Trade Not Aid” initiative, Pax Silica should aim to build infrastructure and trade relationships with the potential to prove commercially profitable for American enterprises in the long run. Congress should fund the program to the requested level of $250 million.
Problem: The PRC and other adversaries may seek to steal exported AI technology through direct diversion. The U.S. Government rightly bans the PRC and other states of concern from acquiring cutting-edge AI technology, including semiconductors and some software. Nvidia’s most advanced chips, called Blackwells, for example, are banned, as is its most advanced chipmaking software (Capoot, 2025; Sutter, 2025). But these are critical resources in the AI race that the PRC clearly seeks to steal.
The Department of Justice has taken action against individuals smuggling chips and software. In December 2025, U.S. authorities shut down a chip smuggling network moving at least $160 million in export-controlled AI chips (Department of Justice, 2025). In January 2026, a former Google engineer was convicted of stealing “thousands of pages of… Google’s trade secrets related to artificial intelligence” at the request of Chinese intelligence (Department of Justice, 2026a). In March 2026, three individuals were charged with trying to divert millions of dollars of export-controlled AI chips to the PRC through Thailand (Department of Justice, 2026b). Diversion operations like these have kept the PRC from falling irrecoverably behind in the AI race, along with other illegitimate means of competing like distillation attacks against American companies (OpenAI, 2026).
The export controls that aim to prevent advanced chips from reaching the PRC are administered by the Department of Commerce’s Bureau of Industry and Security (BIS). But enforcement is challenging as it is difficult to determine the true end-use customer of shipments, particularly once they leave the U.S. This challenge is why even high-profile projects like the U.S.-UAE data center campus agreement brokered by President Trump contain what Commerce Secretary Howard Lutnick called “strong security guarantees to prevent diversion” (U.S. Mission UAE, 2025).
Solution: The Department of Commerce should require packages with controlled AI technology to be exported with location verification technology. The AI Action Plan asks various offices to collaborate with industry to use “location verification features” of advanced AI chips to “ensure that the chips are not in countries of concern” (Kratsios et al., 2025). In brief, location verification would allow BIS to securely estimate the location of chips to verify they have not been diverted to the PRC. Chipmaker Nvidia has pioneered location verification through its “confidential computing” tools (Nellis et al., 2025). Location verification need not be intrusive nor expensive. According to one report, entirely software-based location verification methods based on landmark ping delays could be implemented for all relevant chips for as little as $1 million over several years (Brass et al., 2024). This would enhance enforcement against physical diversion and deter smuggling attempts.
Companies seeking to export advanced chips outside the U.S. must receive export licenses from BIS. The Secretary of Commerce could approve AI export packages containing controlled technology only if they use location verification to which BIS is given access. Alternatively, Congress could require BIS to do the same. BIS must receive this data in a structured, digital, and scalable format so that it can be used effectively in enforcement.
Problem: The PRC and other adversaries may seek to steal computing capacity through remote access (cloud diversion). The computing capacity provided by large data centers of controlled chips can be accessed remotely from anywhere in the world. Although this often precludes the most sensitive applications, such as by militaries, this so-called cloud computing is another target for Chinese theft of American technology. In 2025, for example, a Chinese company purchased access to a huge data center of 2,304 export-controlled Nvidia Blackwell chips located in Indonesia (Morales, 2025). More recently, the PRC’s ByteDance has used a $2.5 billion data center with 36,000 Blackwells located in Malaysia (Shilov, 2026). This usage is not illegal, though Congress has tried to patch this so-called “cloud loophole” through the Remote Access Security Act, which passed the House of Representatives in 2025 (H.R.2683, 2025). BIS has also recently tried to harden its rules against some cloud diversion to the PRC, though enforcement remains a challenge (Guo et al., 2026).
Cloud access for our adversaries clearly violates the spirit of the AI Exports Program. The Program’s goal is to counter the PRC’s influence in AI and ensure other markets use American technology. It would fail to do so if it financed infrastructure PRC companies use to compete in the AI race. Just as important, American taxpayers should not bankroll computing power that is used by the PRC. So, projects developed with support from the AI Exports Program must be secured from cloud diversion.
Solution 1: The Secretary of Commerce should approve only AI Exports Program data centers operated by U.S.-approved companies that agree not to divert capacity to the PRC. Data center operators can verify that large workloads do not originate from the PRC through “know your customer” (KYC) requirements. Data center operators would be required to verify the identity of clients for large workloads. BIS already requires KYC for cloud providers seeking export licenses under some conditions, though not in most cases (BIS, 2026). The Secretary could decide only to approve applications that agree to implement robust KYC measures that would ensure their cloud capacity is not diverted to the PRC. This condition should apply only to large data centers, such as those hosting 1,000 H100-equivalents in computing power or more.
Solution 2: Congress could ban remote access diversion to the PRC. Cloud diversion is perhaps the most significant blind spot in America’s campaign to deny the CCP, its companies, and its military access to advanced AI computing. The capacity of computing facilities that will soon become available to Chinese companies, like the $2.5 billion data center in Malaysia described above, is staggering (Shilov, 2026). Congress could explicitly extend physical chip export controls on advanced AI chips to apply to remote access through cloud computing, preventing the PRC from accessing our most advanced chips.
Solution 3: Congress could require large AI cloud infrastructure outside of the US to implement workload verification systems shared with BIS. The PRC’s history of transshipment and export control evasion motivates a trustless verification approach to new controls. But for cloud infrastructure, location verification is not useful because chips are not physically diverted. Workload verification is a promising alternative.
Workload verification refers to a variety of technical methods by which third parties can verify that computing resources are not being used for unauthorized purposes. One option is to require data center operators to distinguish between AI training and inference workloads in a privacy-preserving way. To do so, operators could observe the rate of data transfer between server racks in certain data centers. Inference uses far less bandwidth than training, so this could verify users’ claims about workloads and prevent unauthorized training—which is arguably a more salient national security concern than inference (McClure et al., 2026). Alternatively, they could collect power signatures and other metrics that could be compared to training and inference footprints, for instance through machine learning classifiers (Jain et al., 2026). Another option, which may be more robust to efforts by users to disguise their workloads but less privacy-preserving, is to conduct randomized “re-executions” of large workloads (Rinberg et al., 2026). This would allow providers or BIS to ensure customers are not rerouting cloud workloads to Chinese companies or the country’s military.
In certain circumstances, BIS may also seek to verify that specific inference workloads adhere to some criteria. For example, infrastructure provided as part of the AI Exports Program might be required to run U.S. models; those requirements could be enforced through verification. Several companies have developed technology that uses confidential computing built into Nvidia chips that allows an auditor to receive cryptographic proof that a particular model is being used without learning anything about the task itself (Lucid Computing, n.d.; EQTY Lab, n.d.). BIS could use technology like this to verify that infrastructure supported by the AI Exports Program uses American models or that certain cloud infrastructure is not using prohibited models, such as those used by the PRC’s military.
Whatever the method employed, workload verification should be reported to BIS in a digital, structured format consistent with modern data analysis practices. The Secretary of Commerce could direct BIS to begin developing standards for workload verification and classification in collaboration with industry that could later be used in export rules.
Summary of Policy Recommendations
The American AI Exports Program and Pax Silica are the United States’s premier initiatives to promote and secure America’s AI tech stack abroad. Both were created in 2025 under President Trump. They could become cornerstones of America’s AI policy for many years if implemented well.
Our recommendations to improve these programs are in three categories: (1) ways to improve their funding and incentives for participation, (2) new provisions to protect American business while exporting, and (3) new security guarantees to prevent physical and cloud diversion.
Funding and Incentives
- The President could direct the U.S. Export-Import Bank (EXIM) and International Development Finance Corporation (DFC) to reserve up to a quarter ($75 billion) of their remaining lending/investment limits for the AI Exports Program.
- The Department of Commerce could incentivize companies to participate in the AI Exports Program by granting them equity in AI-related projects developed via required foreign investments from trade agreements.
- The Department of Commerce could create a unified AI chip export licensing process linked to participation in the AI Exports Program.
Protecting American Business
- Congress could ban government agencies and government contractors from using Chinese-origin AI technology.
- Congress could enhance international export controls on semiconductor manufacturing equipment (SME), including immersion DUV lithography machines and other SME critical for cutting-edge production.
- The Department of Commerce could work with Pax Silica partners, particularly the Netherlands and Japan, to ban critical SME sales to the PRC.
Security Guarantees
- Congress could invest in the Pax Silica Fund and use it to incentivize investment by partner governments and private companies in alternative AI supply chains.
- The Department of Commerce could require export packages containing controlled AI technology to be exported with location verification technology that is accessible by the Bureau of Industry and Security (BIS) in a structured, digital, and scalable format.
- The Secretary of Commerce could approve only AI Exports Program-supported data centers that agree not to sell capacity to the PRC and other countries of concern and to enforce this with “know your customer” (KYC) methods.
- Congress could extend physical export controls on advanced AI chips to apply to remote access through cloud computing, preventing the PRC from accessing our most advanced chips.
- Congress could require large AI cloud infrastructure outside of the US to implement workload verification systems that enforce restrictions on Chinese remote access to AI data centers.
- The Secretary of Commerce could direct the Bureau of Industry and Security (BIS) to develop standards for workload verification.
Conclusion
The Trump Administration has promoted the American AI industry domestically by removing barriers to innovation. In 2026, it is turning to implementing new programs that will promote the American AI industry abroad as well. For these programs to succeed and best serve the American people, they should have more funding and incentives for participation, more strongly protect American business, and secure exports from diversion. With these changes, they will bring global American AI dominance, export American values as well as technology, and stop the PRC from free riding off American innovation.
Resources