Comment on FAR Semiconductor Prohibition (Case 2023-008)
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- The semiconductor prohibition creates supply chain verification requirements that parallel AI behavioral safety credentialing infrastructure.
- Hardware provenance and AI behavioral safety should be verified through complementary credentialing mechanisms.
- Federal contractors need a standardized pathway to demonstrate AI system compliance — not just semiconductor sourcing compliance.
+ Jump to Section
I. The Reasonable Inquiry Standard Is Insufficient for AI Hardware
The proposed rule establishes a "reasonable inquiry" standard under which contractors must identify the source of semiconductor products in their offerings. The FAR Council explicitly declined to require detailed provenance tracking or third-party audits. We respectfully disagree, at least as applied to AI systems.
The AI hardware supply chain presents unique verification challenges: a single AI accelerator chip may involve design in one country, fabrication in another, packaging in a third, and integration in a fourth. The entities listed as covered — SMIC, CXMT, and YMTC — participate at various tiers. Self-certification by a prime contractor cannot reliably verify provenance across these tiers.
II. Lessons from Section 889 Implementation
The proposed rule's self-certification approach mirrors Section 889's prohibition on certain telecommunications equipment. The experience under Section 889 is instructive: federal oversight efforts documented cases where self-certification failed to prevent covered equipment from entering federal supply chains. Contractors certified compliance in good faith but lacked supply chain visibility.
The semiconductor supply chain is more complex and less transparent than telecommunications equipment. If self-certification proved insufficient for identifiable equipment manufacturers (Huawei, ZTE), it will prove even less reliable for semiconductors embedded at sub-component levels across a global fabrication network.
III. Recommendations
1. Establish a voluntary third-party verification pathway for AI hardware provenance. Contractors who obtain third-party verification would receive a rebuttable presumption of compliance with the reasonable inquiry standard. This mirrors FedRAMP and CMMC — neither was mandated initially; both evolved from voluntary to required as the threat landscape matured.
2. Define "reasonable inquiry" standards specific to AI hardware. For AI accelerators, GPUs, TPUs, and inference processors, supplementary guidance should address multi-tier fabrication visibility, not merely first-tier supplier certification.
3. Require AI-specific reporting. The proposed 72-hour reporting requirement should include AI-specific fields: chip architecture, training vs. inference use, and computational capacity thresholds that identify national security-relevant AI hardware.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on GSA AI Clause Basic Safeguarding (GSAR 552.239-7001)
Offers six recommendations on GSA's proposed AI clause for federal procurement, arguing it creates compliance obligations without any mechanism for standardized, verifiable compliance demonstration. Proposes a FedRAMP-style 3PAO credentialing pathway and a critical distinction between behavioral safety and ideological content moderation.
FTC/DOJComment on FTC/DOJ Antitrust Guidelines for Collaborations Among Competitors
Urges DOJ/FTC to provide clear antitrust safe harbors for AI credentialing standards development organizations — addressing the gap where credential denials risk being characterized as group boycotts. Proposes four specific safe harbors for SDO standards, collective AI threat intelligence, credentialing decisions, and insurance-linked credentialing.