Commerce Dept. gets sweeping power to embed tracking in exported chips
S. 1705 — Chip Security Act · Filed by Tom Cotton (R-AR) · 21 cosponsors · Introduced May 8, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the U.S. Department of Commerce to mandate that advanced computer chips exported abroad include built-in security features—primarily location-tracking technology—to prevent theft, diversion, or unauthorized use. The bill also directs the Commerce Department to study additional security measures over the next year and implement them if deemed necessary, with annual reviews to assess new technologies. The stated goal is to protect U.S. national security and competitiveness while potentially allowing more flexible export rules to allies if chips meet security standards.
Why we flagged it
The bill's core function is to impose mandatory security mechanisms on exported advanced semiconductors as an export-control enforcement tool. While framed as national security, the operative mechanism is a regulatory mandate on chip design and export licensing, not a traditional appropriations or commemorative measure.
What the text implies
- The bill grants the Commerce Department broad authority to mandate chip modifications (including 'workload verification' and 'functionality modification') without specifying technical standards, performance thresholds, or public notice-and-comment procedures, creating risk of regulatory overreach or unintended performance/security side effects.
- Location-tracking and anti-tampering mechanisms embedded in chips may create new cybersecurity vulnerabilities or attack surfaces if not carefully designed; the bill requires cost-benefit analysis but does not mandate independent security review before implementation.
The full analysis lists 5 implications of this text.
Who stands to gain
U.S. semiconductor manufacturers (compliance cost recovery, potential market protection); Defense and national security contractors (enhanced export control enforcement); Cybersecurity and hardware security firms (potential contracts for mechanism design/audit)