Biden Divides the World Into Three Tiers of AI Chip Access
The White House unveils its most ambitious export regulation yet: 18 allies face no restrictions, the rest get country-by-country caps, and closed model weights come under control. Just a week before the change of administration.
On 13 January 2025, the Biden-Harris Administration announced an interim final rule, the Framework for Artificial Intelligence Diffusion, published in the Federal Register on the 15th. It expands controls on advanced-computing integrated circuits and creates a control for the weights of certain advanced, closed-weight, dual-use AI models, alongside licence exceptions and validated-user authorisations.
The Bureau of Industry and Security release justifies the framework through proliferation risks, offensive cyber operations and abuses such as mass surveillance. That is the issuing agency’s position. The operational novelty lies in combining destination licensing, national allocations, low-risk exceptions and controls on certain model weights.
A world moving at three speeds
The rule sets out six mechanisms that, in practice, sort countries into three broad categories.
At the top, 18 foreign allies and partners — plus the United States — appear in the country supplement for the new Artificial Intelligence Authorization. The AIA licence exception permits certain exports, reexports and in-country transfers of controlled chips without a specific licence. It does not mean “purchases without any restriction”: product scope, end user, end use, records and the other EAR conditions still apply.
At the opposite end are the so-called "countries of concern," which the rule aims to shut out of the most advanced AI systems and the computing power needed to train them. Here, the message is one of direct containment.
Between these two poles sits the rest of the world, subject to caps and a verified end-user system that determines how much computing capacity each player can accumulate.
A "fast lane" for small orders
One detail that should not get lost in the geopolitics is the Low Processing Performance exception. The legal text defines it through the circuits’ aggregate total processing performance, not a universal number of GPUs: below the threshold and outside arms-embargoed destinations, certain transactions may use the exception and do not consume the country allocation. “Roughly 1,700 GPUs” is therefore not a universal legal threshold: the conversion depends on the particular circuit.
The White House notes that this category covers orders from universities, medical institutions, and research organizations for clearly benign purposes. The stated goal is to speed up low-risk shipments, framing the change as an improvement over the previous status quo.
Verified end users: the new passport for compute
The administrative core of the rule is its "verified end user" system, which allocates permissions based on where a company is headquartered and what security standards it meets.
- Universal Validated End User (UVEU). Authorised entities had to keep at least 75% of their controlled advanced chips in the United States and AIA countries, and could not install more than 7% in any one country outside that group. US-headquartered entities had to keep at least 50% in the United States, according to the official BIS summary.
- National Validated End User (NVEU). An entity headquartered outside an arms-embargoed destination could seek authorisation for data centres in specified locations and at specified scales, subject to security and anti-diversion requirements. The rule does not define that authorisation as “320,000 GPUs over two years”; it uses locations, scales and processing performance.
- Entities without VEU authorisation outside close allies. Where a licence was required, applications began under a presumption of approval until the destination’s cumulative total processing performance reached its allocation; a denial policy then applied. Arms-embargoed destinations retained a presumption of denial regardless of quantity.
A diplomatic lever sits on top: the framework allowed a higher country allocation for destinations providing government-to-government assurances. It was not a universal right to “double to 100,000 GPUs”: the published rule states allocations in total processing performance, not a fixed graphics-card model.
The logic is familiar: turning access to silicon into a bargaining chip for exporting not just hardware, but also standards and alliances.
Not just chips: model weights, too
One of the most novel aspects is that the regulation no longer deals solely with semiconductors. For the first time at this level of detail, it wades into model weights — the numerical parameters produced by training that constitute, in effect, the learned "intelligence" of an AI system.
The new 4E091 classification reaches the parameters of certain closed-weight models trained with 1026 operations or more, with technical exclusions tied to the most capable published model. The figure and conditions are in the Federal Register rule; not every closed model or weights file automatically falls under the control.
There is an explicit exclusion: 4E091 does not control parameters that are “published” under the EAR definition. It also excludes some models derived from a published one, unless additional training exceeds specified thresholds. “Open” here is therefore not an informal label or necessarily the same as open-source code: what matters is whether the parameters have been published in the rule’s legal sense.
At the same time, the rule maintains the requirement that advanced semiconductors sold abroad not end up being used by countries of concern to train advanced AI systems, while still permitting access for general-purpose applications ranging from telecommunications to banking.
Continuity of a long-running strategy
The rule doesn't emerge in a regulatory vacuum. According to the White House, it builds on the chip controls from October 2022 and October 2023 and follows ten months of engagement with lawmakers from both parties, industry representatives, and foreign allies. The stated intent to build bipartisan support and consult with the industry is, in itself, an acknowledgment of how delicate this terrain is.
The central argument recurs throughout the text: don't offshore a critical technology, and make sure the global AI infrastructure depends on American technology. It's a bet on combining openness toward allies with closure toward rivals, calibrating each tier of access.
A legacy with a week left on the clock
The timing matters: the rule was announced days before the change of administration. It became effective on 13 January 2025, but the text delayed general compliance until 15 May and accepted comments through that date; three security provisions had a January 2026 deadline. It was an effective rule with post-publication review, not a general obligation fully enforceable from announcement day.
For industry, preparation starts immediately even though general compliance has a four-month runway. Chipmakers, clouds and data centres must classify the circuit, destination, end user, aggregate processing performance and applicable exception. Outside AIA destinations, access to large installations depends on licences, allocations or VEU authorisations, not a simple three-colour geopolitical passport.
The big question the rule leaves open is its own survival. An interim regulation published in the final stretch of an administration is exposed to being revised, tightened, or loosened by the next one. What is fixed, though, is the conceptual framework: dividing global access to AI by tiers of trust, treating chips — and now also the weights of closed models — as strategic national security assets.
This article was produced with artificial intelligence under human editorial oversight.