Your Export Control Check Probably Ends At Delivery

Taiwan has charged nine people over 130 AI servers diverted to China on false paperwork. Vendor accreditation and a signed end-user certificate both stop at delivery. What a live provenance record catches that a closed file cannot, and why this runs on a separate clock from the AI Act.
AI generated image - empty loading dock with a shipping manifest on a hook, illustrating an export control record that ends at delivery

Nine people. Not a company, not a country. Nine named individuals, and that detail is worth sitting with before anything else about export control.

Taiwanese prosecutors in Keelung have charged nine people over the illegal export of 130 high-end AI servers to China. Those charged include an employee of Nvidia’s Taiwan unit and two former employees of Super Micro’s Taiwan unit. According to the indictment, false end-user documentation stated the servers, fitted with Nvidia chips restricted under US export rules since 2022, would stay in Taiwan. In practice, seventy-four reached Chinese customers, moving through direct shipment and transhipment via Indonesia, Japan and Hong Kong. Taiwan customs stopped the remaining fifty-six at the border after officials found irregularities in the paperwork.

Nvidia says it will work with the authorities to resolve the allegations. Super Micro says its own cooperation led to the arrests and that the company is not a target of the investigation.

So neither company stands accused of building the workaround. Employees do. That is the harder problem for anyone buying AI hardware at scale. A vendor’s export control programme can be genuinely rigorous and still fail to stop someone inside it from acting alone.

Your export control check probably ends at delivery, not at the ship

In EU compliance functions generally, the export control conversation happens at the procurement stage. A vendor gets checked before the contract is signed. The licence terms get read. Once the deal closes, the file moves to the archive. Keelung’s indictment, in other words, describes exactly that file closing correctly while the servers left anyway.

Prosecutors allege that individuals inside two companies with rigorous internal control procedures generated false paperwork. This happened, allegedly, after the point where due diligence typically stops looking. So the compliance programme is not the allegation here. The people operating inside it are.

For that reason, the distinction matters for anyone who signs off a hardware order once the vendor’s export credentials clear.

Three checks that stop at delivery

The signed end-user statement

An end-user certificate is essentially a promise about where equipment will sit. Prosecutors allege the certificate covering these 130 servers named a rented facility in Taiwan, and that the statement was false from the outset. A signature only confirms intent at the point of signing, however. It says nothing about the container six weeks later, once the servers are already at sea.

Vendor accreditation

Both companies involved carry export control programmes that prosecutors themselves describe as rigorous. Accreditation therefore tells you the vendor’s controls are well designed. It does not, though, tell you whether an individual inside that structure chose to route around them. That is exactly the allegation in this case. In short, accreditation was never built to catch it.

The one-time licence review

Compliance teams typically check licence status once, generally before the purchase order is raised. Nothing in that step continues once the equipment ships. Nothing in this indictment, moreover, suggests the underlying licence regime failed. Instead, what allegedly failed is the paperwork describing where the hardware would end up, well after the licence review had already closed its file.

What a live record adds that a closed file cannot

A due diligence file that closes at delivery cannot answer the question a regulator eventually asks. Where is the equipment now, and does that location still match the declaration? By contrast, organisations that keep hardware provenance open past delivery can actually answer that question when it lands on their desk.

  • Track the declared destination against the delivered one. A facility address on an end-user certificate is a claim, not a fact confirmed by delivery. So where you have the standing to request it, ask for confirmation the equipment reached the stated site.
  • Watch the routing pattern, not only the final destination. The alleged route ran through Indonesia, Japan and Hong Kong before some servers reached China. Unnecessary intermediate stops are a signal in themselves, regardless of what the final destination on paper says.
  • Separate the vendor’s controls from the individual’s conduct. A vendor’s compliance record answers whether the company’s systems are sound. It says nothing, however, about whether the specific person handling your order is actually operating inside them. Treating the two questions as one is exactly where this kind of exposure gets missed.

None of that calls for a new department. Instead, it calls for treating hardware provenance as a live record. Not a document filed away the day the equipment leaves the warehouse.

Export control runs on a different clock from the AI Act

This year, compliance attention has understandably gone toward the Digital Omnibus on AI, given its deferred deadlines running through 2027 and 2028. That instrument governs what an AI system must do once it exists. However, it has nothing to say about how the hardware underneath that system reached your organisation.

In fact, an organisation can be fully aligned on every AI Act obligation on its roadmap. It can still have no live answer to where its accelerators came from, or whether they left an authorised jurisdiction cleanly. Supply chain integrity, after all, runs on its own clock. It does not wait for the next AI Act deadline to matter, and consequently export control exposure does not appear on any AI Act roadmap at all.

The question for procurement and governance together

For your organisation’s AI hardware, past the point of delivery, who still owns the answer to where the equipment actually is?

If the honest answer is nobody, that gap sits outside any AI Act timeline and inside ordinary supply chain governance. In other words, export control due diligence that closes at the purchase order is a paper exercise dressed as a control. This week’s indictment, then, is a reasonable prompt to check which one your organisation is currently running. Nine defendants and a rented facility that never held the servers it was declared for are prompt enough. So start that check now, rather than waiting for the next headline to raise it again.

Newsletter
Releted Blogs
LATEST NEWS

AI governance is not a future problem

Regulation is already in effect. Your competitors are already building internal capability. The gap between ‘we are aware of AI’ and ‘we have operational control’ is closing, and it closes faster with a structured framework.

 

Book a 30-minute discovery call. No obligation. We will assess where your organisation stands and what a realistic starting point looks like.

No sales pressure. No jargon. Just a structured conversation about your organisation's AI readiness.

Scroll to Top