The AI chip export ban on China is now a licensing regime
- Authority
- U.S. Department of Commerce, Bureau of Industry and Security (BIS)
- Rule type
- regulation
- Jurisdiction scope
- US federal
- Effective date
- Jan 15, 2026
- Source text
- Read primary rule text ↗
Case-by-case license review conditioned on paragraph (dd) certifications: domestic-supply sufficiency, 50% cap on China/Macau shipments vs US end-user shipments, pre-shipment independent lab testing, consignee KYC, and IaaS remote-user blocking.
If the working question is whether the AI chip export ban on China is over, the legally useful answer is no. As of Q3 2026, for US controls affecting China and Macau, the operative change is narrower: certain advanced computing chips below the specified performance thresholds moved from a presumption-of-denial policy into case-by-case license review, and that review now comes with a certification stack that has to be built before shipment or covered remote access. This tracker is last verified through July 2026 and is not legal advice.

| Question for the transaction file | Current-state answer through July 2026 |
|---|---|
| Is there a blanket green light for AI chips to China or Macau? | No. The January 2026 rule created case-by-case license review for a defined threshold class; it did not remove licensing. |
| Which threshold class is the main January 2026 change? | Advanced computing semiconductors below TPP 21,000 and total DRAM bandwidth 6,500 GB/s — described by BIS using NVIDIA H200 / AMD MI325X-type examples as orientation — are the class now eligible for case-by-case review when otherwise within the rule’s scope.[1][2] |
| What carries the workload in that lane? | New paragraph (dd) certifications: domestic-supply sufficiency, a China/Macau shipment cap tied to US end-user shipments, independent lab testing before each shipment, consignee KYC against prohibited remote users, and IaaS remote-end-user blocking.[1][2] |
| Do reexports from third countries to China or Macau get the same treatment? | No. Morgan Lewis reads the January rule as leaving reexports from third countries to China or Macau under the presumption-of-denial lane.[3] |
| Do D:5-headquartered or D:5-parented parties get the case-by-case lane? | No. Transactions involving a D:5-headquartered or D:5-parented party remain in the denied lane, and that lane remains keyed to ECCN 3A090.a/.b/.c and 4A090.[3] |
| Does the Section 232 tariff decide whether the export is lawful? | No. It is a cost and exemption layer. It does not replace the EAR licensing analysis. |
The January 2026 rule changed the review policy, not the need for a license
The load-bearing text is the Federal Register rule effective January 15, 2026, and the BIS release dated January 13, 2026. For the relevant class of advanced computing commodities destined for China and Macau, BIS revised the license review policy from presumption of denial to case-by-case review when the item is below TPP 21,000 and total DRAM bandwidth 6,500 GB/s.[1][2]
That threshold matters because it is the first sorting question. A sales team may describe a part by commercial name; the export file needs the ECCN, technical parameters, destination, end user, and end use. The H200 and MI325X references are useful signposts, not substitutes for classification and threshold work.[2]
Case-by-case review also does not mean “available if we ask nicely.” It means BIS will review a license application under specified conditions, and the exporter must be able to support the certifications that paragraph (dd) now requires. Those certifications are not decorative attachments. They are the operational control points that determine whether the transaction can be released.

What the paragraph (dd) certifications require
| Certification element | Compliance consequence |
|---|---|
| Domestic-supply sufficiency | The exporter must certify that the transaction will not impair sufficient domestic supply. This is a supply-allocation control, not just a destination screening check.[1][2] |
| 50% shipment cap | Shipments to China and Macau must stay at or below 50% of the exporter’s shipments to US end-users. The practical issue is denominator discipline: the exporter needs a defensible count of US end-user shipments and China/Macau shipments before shipment release.[1][2] |
| Independent testing before each shipment | A US-headquartered, financially independent laboratory must test before each shipment. The rule therefore creates a shipment-by-shipment evidence requirement, not a one-time product family memo.[1][2] |
| Consignee KYC | The consignee must be vetted to block prohibited remote users. For an export manager, this is where customer questionnaires, contractual undertakings, and escalation rules become part of the license file.[1][2] |
| IaaS remote-end-user blocking | Infrastructure-as-a-service access must be controlled so prohibited remote end users cannot obtain covered access. For cloud and data center operators, the transaction is not finished when hardware lands; remote access remains part of the control surface.[1][2] |
The 50% cap is easy to misstate and painful to administer. It is not a 50% cap on all global shipments, and it is not a soft quota that can be fixed after booking. It compares China/Macau shipments against shipments to US end-users. A quarter-close purchase order that would push the exporter over that ratio is not a mere commercial prioritization problem; it is a licensing-condition problem.
The lab-testing condition has a similar effect. If the file only contains an old engineering report, a vendor specification sheet, or a prior shipment test, it does not answer the condition as described. The rule’s phrasing puts the test before each shipment, by a US-headquartered and financially independent lab.[1]
For IaaS and hosted compute, the harder question is often not where the server sits but who can use the compute and from where. The consignee KYC and remote-user blocking conditions pull identity, access management, geolocation, account ownership, resale, and remote administration into the export-control workflow. A cloud-access arrangement can be a compliance event even when nobody is packing a crate.
The lanes ordinary “ban lifted” coverage tends to blur

The January 2026 case-by-case lane is not portable to every China-nexus transaction. The transaction file has to separate at least three issues before anyone treats the more favorable review policy as available: whether the movement is an export or a reexport, whether a D:5-headquartered or D:5-parented party is involved, and whether Entity List or foreign direct product rules independently control the transaction.
| Lane | Do not import the January 2026 case-by-case answer if… |
|---|---|
| Third-country reexports to China or Macau | The item is being reexported from a third country to China or Macau. Morgan Lewis identifies those reexports as remaining subject to presumption of denial.[3] |
| D:5 party involvement | A party is headquartered in, or parented by an entity headquartered in, a D:5 country. Those transactions remain in the presumption-of-denial lane.[3] |
| ECCN 3A090 / 4A090 denied lane | The item falls in ECCN 3A090.a, 3A090.b, 3A090.c, or 4A090 and the relevant facts place it in the denied policy bucket. The January rule did not erase that structure.[3] |
| Entity List and FDP exposure | A listed entity, listed affiliate, or foreign direct product rule fact pattern independently triggers restrictions. The product threshold review does not cure a prohibited party or covered FDP problem. |
That distinction matters most in distribution chains. A US manufacturer may focus on its direct export. A distributor may later reexport from Singapore, Taiwan, Germany, or another third country to China or Macau. If the reexport lane remains presumption of denial, the January 2026 case-by-case policy for direct exports does not answer the downstream transaction.
The same discipline applies to party screening. A D:5-parented purchaser, reseller, financing party, or cloud customer is not made lower-risk because the chip sits below the TPP and DRAM-bandwidth thresholds. The party fact can move the transaction into a harsher lane before the exporter reaches the paragraph (dd) certification checklist.[3]
Entity List and foreign direct product issues sit alongside this analysis, not underneath it. Morrison Foerster’s February 2026 export-control analysis flags Huawei Ascend-related guidance and counter-diversion red flags as continuing parts of AI-chip ecosystem risk management.[4] In practical terms, a clean threshold analysis does not excuse a dirty party screen, suspicious routing, unexplained remote access, or a customer story that does not match the compute being purchased.
This is the same structural problem that appears in other controlled supply chains: one legal track may govern eligibility, another may govern certification, and another may govern cost or litigation exposure. For comparison, the site’s Turkey F-35 statutory gating tracker separates certification and waiver gates from policy preferences; the same separation is useful here.
Why the pre-2026 timeline still matters
Q3 2026 files inherit a layered regime. The point of the timeline is not nostalgia; it is avoiding the mistake of reading the January 2026 rule as if it were the first and only control.
| Date | Why it still shows up in compliance work |
|---|---|
| October 2022 and October 2023 | The US advanced computing controls began and then tightened in the earlier AI-chip control rounds. These are the roots of the classification, destination, and end-use review now sitting in transaction files. |
| December 2024 | The US further strengthened advanced computing controls, adding to the layered baseline that companies carried into 2025 and 2026.[5] |
| March 25, 2025 | BIS announced additional restrictions aimed at China’s artificial intelligence and advanced computing capabilities.[7] |
| April 2025 | The US imposed an indefinite export license requirement on NVIDIA H20 chips to China and D:5 countries, a reminder that lower-performance commercial positioning does not remove licensing exposure.[6] |
| May 13, 2025 | The AI Diffusion Rule was rescinded, but that rescission did not eliminate the separate China/Macau controls discussed here.[4] |
| January 15, 2026 | The current case-by-case review policy for the defined threshold class became effective, with the paragraph (dd) certification stack.[1] |
A control matrix that starts only on January 15, 2026 will miss inherited license requirements, red flags, and restricted-party consequences. A matrix that treats every China-bound AI chip as still categorically denied will also be wrong for the threshold class now eligible for case-by-case review. Both errors create bad holds, bad releases, or both.
The Section 232 layer changes cost and exemptions, not export authority
The January 14, 2026 Section 232 proclamation added a tariff layer for semiconductors meeting the same performance-threshold frame, imposing a 25% tariff and identifying exemptions for US data centers, R&D, startups, non-data-center consumer and civil uses, and public-sector uses.[3][4]
That tariff analysis belongs after the licensing lane analysis. A tariff exemption does not authorize an export, reexport, or cloud access arrangement under the EAR. Conversely, a license pathway does not make the tariff issue disappear. The people clearing the transaction need both answers, but they are not the same answer.
For tariff litigation and refund mechanics in a different context, the site’s Amazon tariff-refund appeal tracker is the closer internal analogue. Here, the immediate sequencing point is simpler: do not let the Section 232 exemption table answer an EAR licensing question.
Reported frameworks and legal challenges are not shipment releases
A reported March 2026 draft framework would move toward volume-tiered review, with press reporting describing about 1,000 GB300-class GPUs as potentially receiving “fairly simple review” and about 200,000-unit exports requiring host-government involvement and allied siting.[8] That is useful as a policy signal. It is not a final rule, not a license exception, and not a substitute for the January 2026 rule text.
The legality of the January 2026 conditions has also been contested in commentary. The arguments include whether the conditions function as barred fees under ECRA Section 4815(c), whether they raise Export Clause problems, and whether the Section 232 component exceeds statutory limits. Those arguments may matter if they become litigation and if a court acts on them. They do not make current noncompliance a tolerable operating assumption.
What violation risk looks like when the file is not theoretical
The enforcement record is the part of this regime that makes sloppy shorthand expensive. Operation Gatekeeper, announced by DOJ on December 8, 2025, involved an alleged China-linked AI technology smuggling network, more than $160 million in attempted H100/H200 exports, more than $50 million seized, and guilty pleas.[9] For a compliance lead, the lesson is not that every bad file looks like a smuggling ring. It is that enforcement agencies are already treating high-end AI-chip diversion as a money, logistics, and party-screening case, not just a paperwork defect.
Cadence shows the institutional penalty side. BIS announced a $95 million penalty, alongside $45 million in forfeiture, for unauthorized exports to Chinese entities tied to supercomputer development.[10] That fact pattern sits close to the controls discussed above because it turns on technology, Chinese entities, and advanced computing development rather than a simple box-on-a-ship narrative.
Exyte shows that the enforcement perimeter also reaches suppliers that may see themselves as one step away from the chip. BIS imposed a $1.5 million administrative penalty against Exyte Management GmbH.[11] In a data center and fab ecosystem, equipment, services, financing, and access arrangements can all become part of the controlled transaction record.
Financial institutions should not treat this as someone else’s export problem. Payment timing, borrower identity, consignee changes, suspicious routing, and customer explanations can all matter when a controlled chip transaction is being financed or banked. The site’s Capital One AML review tracker is not an export-control record, but it is a useful reminder that screening duties often sit with the institution that sees the money before it sees the hardware.
The order of review that still works in Q3 2026
- Classify the item or access arrangement. Identify the ECCN and determine whether the item is within the advanced computing controls, including whether it sits below TPP 21,000 and total DRAM bandwidth 6,500 GB/s.
- Identify the destination and transaction type. Separate direct exports to China or Macau from third-country reexports to China or Macau.
- Screen every relevant party. Do not stop at the immediate buyer; check consignees, parents, resellers, financing parties, cloud tenants, remote administrators, and known end users.
- Decide the review lane. If reexport, D:5-headquartered or D:5-parented party facts, Entity List facts, or FDP facts place the transaction in a harsher lane, do not borrow the January 2026 case-by-case answer.
- If the case-by-case lane is available, build the paragraph (dd) file before shipment: domestic-supply sufficiency, 50% cap calculation, independent lab testing, consignee KYC, and IaaS remote-user blocking.
- Run the Section 232 tariff and exemption analysis separately. It affects cost and import treatment; it does not grant export authority.
- Hold the transaction if the evidence does not exist yet. A condition that must be certified before shipment cannot be cured by a memo written after the chip is gone or the remote user has already accessed the compute.
As of Q3 2026, the “ban” has not disappeared. It has become a licensing regime whose hardest work is proving, before shipment or remote access, that the transaction fits the allowed lane.
References
- Revision to License Review Policy for Advanced Computing Commodities, Federal Register, January 15, 2026
- Department of Commerce Revises License Review Policy for Semiconductors Exported to China, Bureau of Industry and Security, January 13, 2026
- BIS Revises Export Review Policy for Advanced AI Chips Destined for China and Macau, Morgan Lewis, January 16, 2026
- Managing Export Control Risks in the AI Chip Ecosystem, Morrison Foerster, February 9, 2026
- U.S. Strengthens Export Controls on Advanced Computing Items, Holland & Knight, December 2024
- United States government imposes indefinite export license requirement on NVIDIA H20 chips to China and D:5 countries, Global Trade Alert
- Commerce Further Restricts China’s Artificial Intelligence, Advanced Computing Capabilities, Bureau of Industry and Security, March 25, 2025
- Reported Draft Rules Signal New Semiconductor Export Controls Framework, Global Trade & Sanctions Law
- U.S. Authorities Shut Down Major China-Linked AI Tech Smuggling Network, Department of Justice, December 8, 2025
- Cadence Design Systems to Pay $95 Million Penalty to BIS for Unauthorized Exports to Chinese Entities Tied to Development of Supercomputers, Bureau of Industry and Security
- BIS Imposes Administrative Penalty Against Exyte Management GmbH, Bureau of Industry and Security
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →