How to Source GPUs Under BIS Export Controls
The US Bureau of Industry and Security’s AI chip export controls have become the most consequential regulatory constraint in the global AI infrastructure buildout. For anyone procuring NVIDIA H100s, H200s, GB200s, or equivalent high-performance accelerators for deployment in Saudi Arabia or adjacent markets, understanding the BIS framework is not optional — it is the difference between a 6-month GPU sourcing timeline and an 18-month one, or between an approved procurement and a denied one.
This guide explains the current regulatory framework, what it means for Saudi Arabia specifically, how to navigate the process, and what alternative silicon options exist for organizations operating under export control constraints.
The BIS AI Diffusion Framework Explained
The US Commerce Department’s Bureau of Industry and Security finalized its “Export Controls on AI Chips and Advanced Computing” rule — commonly called the AI Diffusion Rule — in January 2025. It supersedes the earlier October 2023 chip controls and represents the US government’s attempt to create a global governance framework for advanced AI hardware.
The Core Mechanism: Compute Thresholds
The rule controls exports of chips at or above specific computational performance thresholds, measured in Total Processing Performance (TPP) and performance density. The practical effect: NVIDIA’s A100, H100, H200, B100, B200, and GB200 GPUs all fall within controlled categories. AMD MI300X and Intel Gaudi 3 are currently controlled at lower thresholds.
The critical threshold for country-level restrictions is 1,700 H100-equivalents per transaction (roughly 1.7 exaFLOPS of FP8 compute). Below this threshold, exports to Tier-2 countries face simplified review. Above this threshold, Tier-2 country exports require a validated end-user (VEU) agreement or an individual export license.
The Three-Tier Country System
Tier 1 (Unrestricted): Close US allies — UK, EU member states, Japan, South Korea, Australia, Canada, New Zealand, Taiwan. No compute caps; chips can be exported freely for any legitimate commercial purpose.
Tier 2 (Controlled): Approximately 120 countries including Saudi Arabia, UAE, India, Brazil, Vietnam, Malaysia, and most of the world. Can receive AI chips up to the 1,700 H100-equivalent threshold per transaction without a license. Above that threshold, or for certain end users, a license or VEU is required.
Tier 3 (Prohibited or Severely Restricted): China, Russia, Iran, North Korea, and a handful of other countries. Effectively banned from receiving advanced AI chips regardless of end use.
What Saudi Arabia’s Tier-2 Status Means in Practice
Saudi Arabia’s Tier-2 classification has three practical consequences for GPU procurement:
1. Individual shipments below threshold are straightforward. A company ordering 1,500 H100 GPUs (below 1,700 H100-equivalent) for a Saudi data center can proceed with a standard EAR (Export Administration Regulations) filing without individual license review. This covers small to mid-scale AI deployments.
2. Above threshold, the process gets complex. A hyperscale deployment of 10,000 H100s for Humain or a hyperscaler building a Saudi AI campus requires either a VEU agreement (see below) or an individual license application — a process that takes 6–12 months and may be denied based on end-use and end-user assessment.
3. Ongoing monitoring obligations apply. Even approved exports to Tier-2 countries carry re-export restrictions (chips cannot be shipped from Saudi Arabia to Tier-3 countries), end-use verification requirements, and periodic reporting to BIS. Saudi entities receiving large shipments should budget for legal compliance infrastructure to manage these obligations.
Validated End-User (VEU) Status: The Primary Solution Path
For Saudi entities expecting to procure AI chips at scale on an ongoing basis, obtaining Validated End-User (VEU) status from BIS is the most important step in any GPU sourcing strategy.
What VEU Provides
VEU is a BIS authorization that allows approved entities to receive controlled items without individual transaction-level licensing. Once granted, a VEU-authorized entity can receive chip shipments above the 1,700 H100-equivalent threshold under streamlined review, with agreed end-use restrictions in place.
Major VEU-authorized entities globally include: Samsung (South Korea), TSMC (Taiwan), several European hyperscale operators. Humain, Saudi Arabia’s PIF-backed AI entity, has pursued VEU authorization as part of the 2025 US-Saudi AI cooperation framework. G42 in UAE also pursued VEU authorization following its 2024 restructuring to remove Chinese technology ties.
Steps to Apply for VEU Status
-
Engage a US export control counsel. VEU applications are complex regulatory filings. Budget $50,000–$150,000 in legal fees for a serious application. Firms with strong BIS practices include Baker McKenzie, Gibson Dunn, Akin Gump, and specialist boutiques like Pillsbury Winthrop.
-
Conduct an internal end-use audit. BIS requires applicants to demonstrate: no military end-use, no connections to prohibited entities, robust internal compliance programs, and willingness to accept site visits and audits. Document your compliance infrastructure thoroughly before filing.
-
Submit via BIS’s SNAP-R system. The Simplified Network Application Process Redesign (SNAP-R) is the online filing portal. Your application includes entity information, requested items, end-use descriptions, and compliance program documentation.
-
Respond to BIS clarification requests. BIS commonly issues requests for additional information (RAIs) within 30–60 days of submission. Response speed matters — applications stall when RAI responses are delayed.
-
Expect a 6–12 month process. VEU applications for GCC entities currently average 8–10 months from submission to decision. This timeline reflects increased scrutiny and application volume since the January 2025 rule.
The Diplomatic Channel
For sovereign entities (government ministries, PIF portfolio companies), VEU applications are often accompanied by government-to-government diplomacy. The Humain-NVIDIA partnership, announced in May 2025, included diplomatic commitments from the Saudi government regarding data security and end-use monitoring as part of the arrangement. If you are a government-affiliated entity, engage your foreign ministry’s trade office as a parallel track to your legal VEU application.
Compute Cap Thresholds: Below vs. Above 1,700 H100-Equivalent
Understanding what “1,700 H100-equivalent” means in practice for procurement planning:
| Hardware | Units at 1,700 H100-equivalent |
|---|---|
| NVIDIA H100 SXM | 1,700 |
| NVIDIA H200 SXM | ~1,200 (higher performance per chip) |
| NVIDIA GB200 NVL72 | ~200–250 rack units |
| AMD MI300X | ~1,800 (slightly lower TPP than H100) |
| Intel Gaudi 3 | ~2,400 (lower per-chip performance) |
For most enterprise AI deployments — a large language model inference cluster, a computer vision platform, an analytics workload — you will stay below the threshold in any single transaction. Batch your GPU procurement carefully: split large orders across multiple transactions and multiple quarters to remain below per-transaction thresholds. This is a legal and commonly practiced approach; your vendor’s export compliance team will typically advise on structuring.
Alternative Silicon: Options for Non-US Controlled Hardware
For organizations that need to move faster than the US export license process allows, or for projects where US silicon is unavailable, these alternatives deserve serious consideration:
AMD MI300X
The AMD MI300X is the closest performing alternative to the NVIDIA H100. At 192GB HBM3 memory and 5.3 petaFLOPS of FP8 compute, it exceeds H100 on memory capacity and matches it on most transformer inference workloads. AMD is subject to BIS controls at similar thresholds to NVIDIA, so the procurement path is similar — but AMD’s current market position means less competition for allocation, potentially faster shipping timelines.
Ecosystem note: ROCm (AMD’s compute stack) is less mature than CUDA. Expect 10–20% higher engineering effort to port CUDA-optimized workloads to ROCm. Most major AI frameworks (PyTorch, JAX, vLLM) now have solid ROCm support.
Intel Gaudi 3
Intel Gaudi 3 delivers competitive transformer inference performance, particularly for LLM inference at batch sizes above 32. Available via Intel’s Habana subsidiary. US export controls apply but Intel’s market share and allocation visibility are less constrained than NVIDIA.
Cost advantage: Gaudi 3 systems are typically 30–40% less expensive than equivalent H100 configurations. Hugging Face Optimum Habana provides a software stack for porting models to Gaudi with moderate effort.
Domestic Chinese Alternatives (For Non-US Entities)
For entities that are not subject to US export controls on their procurement — non-US companies, Saudi entities procuring from non-US supply chains — Chinese domestic AI accelerators have reached meaningful performance levels:
- Huawei Ascend 910B: Comparable to NVIDIA A100 on transformer workloads; CANN software stack is separate from CUDA/ROCm ecosystem; full supply chain independence from US components
- Biren BR100: Targeting H100 performance; limited production volume as of 2025
- Cambricon MLU370: Suitable for inference workloads; not competitive for training at scale
Important caveat: Saudi entities receiving these chips must ensure procurement does not create secondary sanctions risk if their operations involve US-dollar transactions or US business relationships. Consult OFAC counsel in addition to BIS counsel for Saudi entities with US business ties.
Timeline and Cost of the Export License Process
For organizations planning large-scale GPU procurement for Saudi deployments, here is a realistic project timeline:
Month 0–1: Engage export control counsel; conduct internal compliance audit; initiate VEU application or individual license application in SNAP-R
Month 1–3: BIS initial review; likely receipt of RAI; prepare and submit response
Month 3–8: BIS substantive review; possible government-to-government consultation (for sovereign entities); site visit preparation
Month 6–12: License decision (approval, denial, or approval with conditions)
Month 12+: Procurement, shipping, customs clearance, installation
Total cost estimate for a full VEU application process:
- Legal fees: $50,000–$200,000
- Compliance program build-out: $100,000–$500,000 (staff, systems, policies)
- Government relations support (for sovereign entities): $100,000–$500,000/year
- Total: $250,000–$1.2 million before the first chip ships
This cost is immaterial relative to the scale of a serious Saudi AI compute deployment (a 10,000-GPU cluster runs $250M–$400M in hardware alone), but it must be planned for explicitly. Companies that treat export controls as an afterthought discover that their entire GPU delivery schedule is built on a regulatory assumption they cannot fulfill.
Practical Procurement Steps for a Saudi AI Deployment
- Determine your total compute requirement and single-transaction sizing strategy
- Identify target hardware and confirm export control classification with vendor
- Engage US export control counsel and initiate compliance infrastructure build
- Apply for VEU (if large-scale, ongoing procurement) or individual license (one-time large purchase)
- In parallel, qualify alternative silicon vendors (AMD, Intel) as backup supply chain
- Structure procurement contracts with export license contingency clauses — do not pay full non-refundable deposits on hardware contingent on pending export licenses
- Plan data center construction timeline to accommodate GPU delivery uncertainty (build facility infrastructure; defer final GPU order placement until license is in hand)
- Establish ongoing BIS compliance program for end-use monitoring and annual reporting
The companies succeeding in Saudi AI infrastructure builds are those that treat export control compliance as a core competency, not a legal checkbox. The regulatory environment will continue to evolve — the January 2025 AI Diffusion Rule will have successor versions — and organizations with in-house expertise will navigate changes faster than those dependent entirely on outside counsel.
Managing GPU Inventory Under BIS Obligations
Once chips are delivered to Saudi Arabia under a BIS license or VEU authorization, your obligations are ongoing. Inventory management for export-controlled hardware differs meaningfully from standard IT asset management.
End-Use Monitoring and Record Keeping
BIS requires license holders to maintain records for five years from the date of export. Required records include:
- Purchase orders and invoices matching chip serial numbers to the licensed transaction
- End-use declarations from the receiving Saudi entity
- Evidence that chips are deployed for the stated end-use purpose (commercial AI compute, not military or prohibited civilian applications)
- Records of any chip disposal, transfer to another party within Saudi Arabia, or decommissioning
For data center operators with thousands of GPU cards, implementing hardware asset management software (ServiceNow IT Asset, Device42, or similar) that tracks individual GPU serial numbers is not optional — it is a BIS compliance requirement. BIS can and does conduct post-shipment verification visits, either directly or through the US Embassy commercial section.
Re-Export Restrictions
Chips exported from the US to Saudi Arabia under BIS license cannot be re-exported to third countries without separate BIS authorization. In practice, this means:
- A Saudi data center cannot sell used H100s to an entity in a Tier-3 country (China, Russia, Iran)
- A multinational with Saudi operations cannot transfer chips from its Saudi facility to a Chinese affiliate without a new export license
- Cloud customers using Saudi-based GPU capacity cannot use that capacity to provide services to sanctioned entities
Document your cloud customer base and implement contractual prohibitions on sanctioned-country usage in your terms of service. BIS has applied controls enforcement to cloud providers that allowed sanctioned-country usage of controlled hardware, treating the cloud service as a deemed export of the underlying controlled technology.
Secondary Sanctions Risk
Beyond BIS regulations, companies operating in Saudi Arabia must also manage OFAC (Office of Foreign Assets Control) secondary sanctions risk. If a Saudi AI project receives investment from or has business relationships with sanctioned parties, US person employees (including US-citizen engineers) working on the project may inadvertently become involved in sanctioned transactions. Conduct counterparty due diligence on Saudi partners through specialized GCC-focused due diligence firms (Control Risks, Kroll, Teneo) before entering significant commercial relationships.
Scenario Planning: What If Controls Tighten
The January 2025 AI Diffusion Rule represented a specific policy calibration at a specific political moment. Technology companies and Saudi entities should prepare for both tightening and loosening scenarios:
Tightening scenario: A future administration lowers the compute threshold from 1,700 to 500 H100-equivalents, effectively requiring export licenses for all large AI deployments. Saudi entities in this scenario would need to rely on previously approved VEU authorizations (grandfathered in) and accelerate alternative silicon qualification. Timeline to full AMD ROCm operational capability: 6–12 months if GPU hardware is available.
Loosening scenario: Saudi Arabia achieves Tier-1 status or equivalent through a formal bilateral agreement. Controls on commercial AI chip exports would effectively disappear. All procurement and compliance infrastructure built for Tier-2 operations would still be valuable — OFAC, customs, and Saudi PDPL obligations remain regardless of BIS classification.
Status quo scenario: The current framework persists with incremental adjustments. Companies with active VEU authorizations maintain their procurement access; new entrants face the 8–12 month VEU timeline. Alternative silicon continues to improve, gradually eroding NVIDIA’s effective monopoly on BIS-relevant AI compute hardware.
Maintain active engagement with US export control counsel, subscribe to BIS Federal Register notifications, and participate in industry working groups (Semiconductor Industry Association, Information Technology Industry Council) that track and respond to BIS regulatory developments. The companies that shape future export control policy are those actively engaged in the regulatory process, not those reading about changes after they happen.