NVIDIA develops chip location verification technology using inference algorithms that could be used to combat AI chip smuggling

Source: The Register
NVIDIA has developed a new location verification feature for its data center GPUs that can estimate which country a chip is operating in, according to a Reuters report. The tool is intended to help combat the smuggling of AI accelerators into markets where U.S. export rules block direct sales, such as China.
The system comes as an optional software agent that customers install in their own data centers. NVIDIA says it uses GPU telemetry and confidential computing features to track the health, integrity, and inventory of the GPU fleet. It then estimates location based on communication latency between the GPUs and NVIDIA-run servers, with accuracy similar to IP geolocation.
The company also says that the service is read-only, so its servers cannot push data back to the GPUs or control them, and there is no way for NVIDIA or anyone else to disable hardware through this feature. NVIDIA plans to open-source the software so outside security researchers can review how it works.
“We’re in the process of implementing a new software service that empowers data center operators to monitor the health and inventory of their entire AI GPU fleet This customer-installed software agent leverages GPU telemetry to monitor fleet health, integrity and inventory.”
“There is no feature within Nvidia GPUs that allow Nvidia or a remote actor to disable the Nvidia GPU. There is no kill switch.”
— NVIDIA to Reuters
All this is happening under tight U.S. export controls on advanced AI chips and a growing gray market around them. Blackwell accelerators cannot be sold to many Chinese entities, so smugglers use third countries to move hardware into restricted markets. U.S. authorities have already filed cases over attempts to send more than $160 million worth of NVIDIA GPUs into China. Location verification is meant to give customers and regulators a clearer picture of where these restricted chips actually end up, even if the tool itself does not enforce export rules or shut anything down.
The new feature also brings back earlier worries about hidden controls in AI hardware. Chinese regulators have questioned NVIDIA in the past about alleged backdoors in export-approved chips, and some U.S. proposals have called for built-in tracking or kill switches.
In August 2025, NVIDIA chief security officer David Reber Jr. pushed back in a post titled “ No Backdoors. No Kill Switches. No Spyware.” He argued that such controls would be a gift to attackers and repeated that NVIDIA GPUs do not have, and should not have, any kind of backdoor or kill switch.
Source: Reuters