C/PAdvanced-compute evidence ledgerWhen Controls Raise the Cost
Defensible MVPEvidence through 03 Sep 2026v0.1.0

China’s Responses to U.S. Advanced-Compute Restrictions

When controls raise the cost.

Since October 2022, which Chinese responses have actually weakened U.S. controls on advanced AI chips, and which have only made Chinese AI development more expensive, slower, or more dependent on outside technology?

08Policy milestones
05Response cases
19Evidence records
31Primary of 33 sources

Case comparison / five records

Test the workaround, not the headline.

Each case receives the same six questions. Use the filters to isolate a response type, time, source class, confidence level, or dependency finding.

Filter the evidence

05 / 05 cases

Selected case · 2024–2025

DeepSeek-V3 on Nvidia H800

Algorithm and systems co-design stretched a restricted H800 fleet, but did not replace the hardware chokepoint.

Adaptation + cost penalty

Foreign-controlled hardware

Q1Demonstrated

Capability restored

A 671B-parameter mixture-of-experts model delivered strong author-reported benchmark results; on METR’s autonomy suite it was comparable to Claude 3.5 Sonnet (Old) while trailing newer frontier models.

Q2Partial

Repeatable scale

One 2,048-H800 training run is documented. Weights and inference code are public, but the full training stack and dataset are not.

Q3Material

Extra resources

The disclosed 2.788 million GPU-hours exclude prior research, ablations, data, staff, acquisition, energy, and failed work. Extensive low-level co-design was required.

Q4High

Outside dependency

Training used Nvidia H800 accelerators and a software/networking stack centered on controlled U.S. technology.

Q5Mixed

Enforcement resilience

Algorithms and weights diffuse readily; installed chips cannot be recalled. Future hardware refresh, HBM, and accelerator replenishment remain enforceable chokepoints.

Q6Unclear

Next generation

The run proves useful 2024-era capability. Later DeepSeek releases do not publicly disclose enough hardware detail to show that the same mechanism scales forward.

Comparison matrix

Four judgments, not one score.

“Genuine weakening” applies only to the control point actually displaced. A domestic accelerator can weaken finished-chip denial while leaving HBM, fabrication, power, and scale unresolved.

Skip comparison matrix
Cross-case matrix comparing capability, cost, dependency, enforceability, and judgment
Response / caseCapabilityCost penaltyDependencyEnforcementJudgment
Compute efficiencyDeepSeek-V3 efficiencyDemonstratedA 671B-parameter mixture-of-experts model delivered strong author-reported benchmark results; on METR’s autonomy suite it was comparable to Claude 3.5 Sonnet (Old) while trailing newer frontier models.MaterialThe disclosed 2.788 million GPU-hours exclude prior research, ablations, data, staff, acquisition, energy, and failed work. Extensive low-level co-design was required.HighTraining used Nvidia H800 accelerators and a software/networking stack centered on controlled U.S. technology.MixedAlgorithms and weights diffuse readily; installed chips cannot be recalled. Future hardware refresh, HBM, and accelerator replenishment remain enforceable chokepoints.Adaptation + cost penaltyModerate confidence
Domestic substitutesPangu domestic trainingDemonstratedHuawei reports training a 718B-parameter model from scratch on Ascend and says its system supports all training stages, with self-reported results near DeepSeek-R1 on several tasks.HighThe run used 6,000 accelerators, about 19 trillion tokens, 30 percent model FLOP utilization, and extensive recomputation, swapping, topology, operator, and simulation work.ReducedAscend and Huawei’s CANN/MindSpeed layers are domestic, but the disclosed stack also uses open-source PyTorch, Transformers, and NVIDIA-origin Megatron-LM. Public evidence does not resolve HBM, fabrication equipment, packaging, optics, or the provenance of every die.MixedDomestic accelerators reduce leverage at the finished-chip layer. HBM, EDA, fab tools, foundry services, and packaging remain alternative control points.Genuine weakeningModerate confidence
Systems engineeringCloudMatrix systems engineeringDemonstratedThe vendor-authored evaluation serves a 671B-parameter DeepSeek-R1 model with little reported INT8 accuracy loss across 16 benchmarks.HighThe complete system uses 384 NPUs, 192 CPUs, a large optical fabric, disaggregated memory, custom collectives, scheduling, quantization, and fault recovery.ReducedHuawei designed the accelerator, CPU, and CANN layers, while the disclosed stack interoperates with PyTorch, TensorFlow, ONNX, and Kubernetes; HBM, fab tools, packaging, and high-speed optics remain unresolved.MixedPooling weakens a per-chip threshold. Aggregate HBM, networking, energy, manufacturing equipment, and production volume remain observable constraints.Adaptation + cost penaltyModerate confidence
Rerouted accessRerouted H100/H200 accessUnknownThe chips could support advanced training and inference, but public court and agency materials do not identify a completed model or workload.MaterialThe route required straw purchasers, intermediaries, mislabeled hardware, false paperwork, warehouses, logistics companies, and large cross-border payments.CompleteThe route depended on Nvidia accelerators and foreign procurement and logistics. It created no domestic technological independence.LowCustomer checks, beneficial-ownership review, shipment inspection, data-center verification, and financial tracing can disrupt this route; this case was disrupted.Circumvention, not independenceModerate confidence
Stockpiling & state supportState support evidence gapUnlinkedNational tax preferences and local compute vouchers support the sector, but no reviewed award record ties them to a specific restored capability in this MVP.UnknownSubsidies may transfer cost to the state without removing real hardware, energy, or time requirements.UnknownA tax preference or compute voucher does not disclose the origin of chips, memory, networking, or fabrication inputs.IndirectFiscal support can absorb higher prices but cannot itself replace a denied component or protect a foreign access route.Insufficient evidenceLow confidence

Policy timeline / Oct 2022–present

The rule in force matters.

Announcement, publication, effective, compliance, suspension, and license-review dates are not interchangeable. Each entry preserves that distinction.

  1. 01Effective in phases

    Foundational advanced-compute and semiconductor controls

    Created advanced-computing ECCNs, China-wide license requirements, supercomputer end-use controls, foreign-direct-product rules, and specified U.S.-person restrictions.

    Caveat: Different provisions took effect on 7, 12, and 21 October; later rules changed thresholds and scope.

  2. 02Effective 17 Nov 2023

    Performance-density and anti-circumvention update

    Recalibrated chip thresholds, added a performance-density test, expanded destination and end-user reach, and tightened equipment and U.S.-person controls.

    Caveat: The Federal Register publication date is 25 October, despite a conflicting date on one legacy BIS page.

  3. 03Effective with split compliance dates

    HBM, manufacturing-equipment, software, and entity package

    Added controls on high-bandwidth memory, more semiconductor-manufacturing equipment, ECAD/TCAD software, additional foreign-produced items, and 140 Entity List entries.

    Caveat: Limited exceptions and delayed compliance mean this was not a universal HBM or equipment ban.

  4. 04AI Diffusion requirements not enforced; formal rescission pending

    AI Diffusion Framework issued

    Added worldwide regional-stability licensing for the most advanced chips and controls on certain closed-weight model weights, with country tiers and exceptions.

    Caveat: Commerce announced non-enforcement and intended rescission before compliance began; preexisting D:5/Macau-headquarters controls remain enforced worldwide.

  5. 05Effective; transition deadlines extended

    Foundry and packaging due-diligence rule

    Required front-end fabricators and OSATs to investigate designers and customers and created trusted-designer and approved-OSAT pathways.

    Caveat: A 2026 amendment extended some designer-status deadlines through 31 December 2026 without removing the core regime.

  6. 06Effective 31 Dec 2025

    Validated End-User authorizations revoked for three China fabs

    Removed Intel Dalian, Samsung China Semiconductor, and SK hynix Semiconductor China from the VEU list, requiring individual licenses for covered items.

    Caveat: BIS stated it would distinguish existing operations from expansion; TSMC was not named in this rule.

  7. 07Suspended through 09 Nov 2026

    Listed-entity affiliate rule issued, then suspended

    Extended certain end-user restrictions to entities owned 50 percent or more by listed parties and imposed ownership diligence.

    Caveat: The automatic affiliates rule was not operative on this project’s 3 September 2026 cutoff date.

  8. 08Effective

    Conditional case-by-case review for H200-class exports

    Moved qualifying direct U.S. exports of H200, MI325X, and similar chips to China or Macau from a presumption of denial to conditioned case-by-case review.

    Caveat: This was not license-free access or general approval; reexports, transfers, volume, end use, testing, and customer conditions remained restrictive.

Two-minute summary

Progress is an outcome. Control failure is a causal claim.

Read the full method

Chinese AI progress is real, but progress and control failure are not synonyms. DeepSeek-V3 shows that efficient model and systems design can stretch a restricted Nvidia H800 fleet. Huawei’s Pangu Ultra shows that thousands of domestic Ascend accelerators can complete a very-large-model training run, weakening the narrow claim that access to top U.S. accelerators is indispensable. CloudMatrix384 shows that system design can recover useful inference performance by pooling many weaker devices. A U.S. prosecution shows that restricted H100 and H200 chips also moved through a diversion network. Each result carries a different implication. The Huawei cases still leave fabrication, high-bandwidth memory, power, networking, and economics unresolved. DeepSeek remained dependent on controlled foreign hardware. Smuggling is an enforcement failure, not technological independence. The strongest current reading is that the controls impose friction and shift costs rather than create an absolute barrier—and that only repeated, independently verified scale can show whether that friction is durable.

Interpretation discipline

Capability, cost, and dependence are scored separately.

A model release can show restored capability while leaving the policy’s delay, resource burden, or upstream leverage intact.

Evidence design

Every claim carries its own objection.

Nineteen cards pair source location and data with counterevidence, confidence, and remaining uncertainty.

Reproducible artifact

The research record is inspectable and downloadable.