Free tools Windows power users keep installed
One-click scans. No signup required.
Assess AI-related trade risk by mapping the technology, suppliers, transaction, jurisdictions, end users and end uses—then checking the relevant controls and documenting what you verified. A review limited to your direct vendor or to a chip’s shipping destination can miss exposure in upstream suppliers, ownership and control, technical data, routing, or diversion indicators. Use a repeatable process, and verify the rules that apply on the date of each transaction.
What counts as AI-related trade risk?
The risk is not limited to shipping an AI accelerator across a border. It can arise from hardware, software, technology, technical data, services, financing, investment, or other activities that support AI development and deployment. Relevant exposure may involve the item’s classification and origin, the parties in a transaction, its destination and route, its end user or end use, or a supplier’s ownership and influence.
Export controls, sanctions and other restrictions vary by jurisdiction and transaction. A supplier review helps identify exposure; it does not by itself determine whether a transaction is permitted or whether a license is required. Escalate uncertain classification, licensing, sanctions or diversion questions to qualified trade counsel or compliance specialists.
How do I assess AI-related trade risks in my supply chain?
- Set the scope. Identify the AI system and the goods, software, technical data, services, financing and business activities that support it.
- Map the chain and transaction. Identify material suppliers and sub-tier dependencies, the relevant parties, and the origin, transit, destination and jurisdictions that may regulate the item, technology, parties or activity.
- Collect and assess evidence. Review supplier ownership and control, provenance, supply-chain tiers, resilience and cybersecurity practices. Record what is verified, what is supplier-asserted and what is unknown.
- Check trade exposure. Identify the item or technology and its applicable classification; check relevant jurisdiction-specific restrictions and licensing rules; screen parties; and assess destination, route, end user, end use and transaction context.
- Prioritize and respond. Apply consistent review criteria, assign decision owners and escalation thresholds, and determine whether to proceed, mitigate, pause or cease activity.
- Monitor and revisit. Track actions and reassess when a supplier, owner, product, destination, route, end use, rule or party-list status changes.
The steps create a documented review, not a universal pass/fail formula. The evidence and applicable rules determine what decision is appropriate for a particular transaction.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What should supplier due diligence cover?
NIST Special Publication 1326, published in 2026, defines due diligence as “the investigative process of researching all available, pertinent information about a given supplier or product so that informed decisions can be made on new acquisitions or existing systems.” Its ICT-focused guide identifies five areas to assess:
- Foreign ownership, control or influence: establish the supplier’s legal identity and ownership or control structure, including relevant foreign influence.
- Provenance: trace the origin and supply path of material products and components as far as practical.
- Resilience: understand dependencies, continuity risks and available alternatives if a supplier or component becomes unavailable.
- Foundational cybersecurity practices: assess relevant supplier cyber practices as part of the risk review.
- Supply-chain tiers: look beyond the direct vendor where practical, including the sub-tier suppliers that provide important components or services.
For each material supplier or product, retain the evidence behind your assessment. Distinguish independently verified facts from supplier statements, identify missing information, and explain whether uncertainty changes the decision or requires follow-up. The appropriate scope depends on the business and transaction; NIST does not supply one checklist that fits every sector.
Rank #2
How do I check an AI chip supplier or customer for export-control risk?
Review the whole transaction, not just the counterparty or the chip name. A practical file should connect the item and its classification to the parties, route, destination, end user, end use and applicable rules. The European Commission’s 2024 due-diligence guidance addresses export-related sanctions and calls attention to risk assessment, business partners, transactions, goods and circumvention red flags. It is useful for that subject, but it is not a complete statement of every country’s export-control or sanctions rules.
- Item and technology: identify what is being supplied, including relevant software or technical data, and establish the applicable classification rather than relying on a broad description such as “AI chip.”
- Jurisdiction and authorization: identify which jurisdictions may regulate the item, technology, parties or activity, then check the operative restrictions and licensing requirements for the transaction date.
- Parties: screen relevant counterparties and consider ownership or control, not only the name on the purchase order.
- Transaction details: record destination and routing, end user, end use and other context needed to assess the transaction.
- Inconsistencies and circumvention: investigate conflicting information about partners, goods, route or use; unresolved red flags should be escalated rather than treated as routine paperwork gaps.
Advanced-computing semiconductors and their supply chains have been a specific focus of U.S. export-control and diversion measures. In a January 15, 2025 announcement, the U.S. Bureau of Industry and Security (BIS) described due-diligence and reporting measures involving foundries, packaging companies, approved IC designers and OSATs, including certain newer customers. Treat that announcement as a dated description, not a substitute for checking the current Export Administration Regulations (EAR), applicable Federal Register actions and current BIS guidance before making a decision.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
How should I handle changing U.S. chip controls?
Do not rely on the original publication of the AI Diffusion Rule announced in January 2025 as evidence that it is currently enforceable. In a May 13, 2025 statement, BIS said it would not enforce that rule, planned to formalize its rescission and intended to issue a replacement. That statement alone does not establish the later status of any replacement or the complete current chip-control regime.
For a live transaction, check the operative EAR text, Federal Register actions, current BIS guidance, relevant country and party restrictions, and licensing requirements. Confirm the position for the specific item, parties, destination, end use and transaction date; a historical announcement may not reflect later amendments or actions.
How do AI due diligence and investment risks fit in?
Trade review can sit within a broader, ongoing AI value-chain due-diligence process. The OECD’s 2026 Guidance for Responsible AI describes a six-step cycle:
- Embed responsible business conduct expectations in policies and management systems.
- Identify and assess actual or potential impacts.
- Cease, prevent or mitigate impacts.
- Track implementation and results.
- Communicate how impacts are addressed.
- Provide for or cooperate in remediation where appropriate.
This process complements, rather than replaces, transaction-level export-control and sanctions checks. For example, a company may track responsible-AI impacts across its value chain while separately determining whether a particular chip, software transfer, service or customer requires a license or other action.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
Consider investment and technology-transfer channels as well as shipments. A European Commission recommendation adopted January 15, 2025 asked EU Member States to review outbound investment involving semiconductors, AI and quantum technologies, including relevant ongoing and past transactions dating from January 1, 2021. It is a recommendation for a Member State review process—not, by itself, a general prohibition on company investment. EU-linked enterprises should establish whether relevant transactions fall within the review and assess any applicable national measures separately.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should I compare and prioritize suppliers or transactions?
Use the same review dimensions across cases so that differences are visible and decisions can be explained. A useful record connects each dimension to evidence and a follow-up action:
| Review dimension | Evidence or question | Decision use |
|---|---|---|
| Jurisdiction and legal regime | Which jurisdictions may regulate the item, parties, technology or activity? | Identify the rules and licensing position to verify for this transaction. |
| Supplier tier and ownership/control | Who supplies the product or service, including relevant sub-tier suppliers, and who owns or controls them? | Determine whether indirect dependencies or foreign influence need further review. |
| Product identity and classification | What goods, software or technology are involved, and what classification applies? | Assess item-specific restrictions and licensing requirements. |
| Provenance | What is known about the origin and supply path of material components? | Identify sourcing uncertainty or dependencies that affect the transaction decision. |
| Destination and route | Where will the item or technology go, and how will it be routed? | Check applicable geographic restrictions and investigate unexplained routing. |
| End user and end use | Who will receive or use the item, and for what purpose? | Evaluate restrictions tied to a party or use and resolve inconsistencies. |
| Sanctions or restricted-party exposure | Are any relevant parties subject to restrictions, including through ownership or control? | Escalate potential matches or other unresolved party concerns for review. |
| Diversion indicators | Do partner, transaction or goods details conflict or raise circumvention concerns? | Seek clarification and escalate material red flags before proceeding. |
| Resilience and alternatives | What dependencies could interrupt supply, and are alternatives available? | Plan mitigations for continuity and concentration exposure. |
| Cybersecurity practices | What relevant foundational security practices are evidenced? | Decide whether cyber gaps require mitigation or additional assurance. |
| Evidence quality | Which facts are verified, supplier-asserted, missing or outdated? | Set follow-up requirements and reflect uncertainty in the decision. |
Set internal owners and escalation thresholds that fit your organization, then record the rationale for action. NIST, OECD, BIS and the European Commission materials cited here do not prescribe one universal numerical risk score. If your organization uses an internal score, label it as an internal prioritization tool—not an official standard—and retain the underlying evidence and judgment.
What should the assessment record and monitoring process include?
A useful record lets another reviewer understand the scope, evidence, decision and what would trigger a reassessment. Keep a dated file that captures:
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches- the AI system, product or activity reviewed and the suppliers and tiers in scope;
- relevant jurisdictions, parties, item or technology classification, destination, route, end user and end use;
- ownership and control, provenance, resilience and cybersecurity findings;
- the sources of evidence, what is verified versus asserted, missing information and any uncertainty;
- applicable rules and licensing checks made for the transaction date, along with unresolved questions;
- identified risks, escalation decisions, approvals, mitigations, pauses or decisions to stop activity;
- responsible owners, follow-up dates, communications and any remediation where appropriate; and
- events that trigger reassessment, such as a change in supplier, owner, product, route, destination, use, applicable rule or party-list status.
Where information is incomplete, document the gap and its effect on the decision rather than silently treating an assertion as verified. Revisit the file when the transaction or its regulatory context changes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

