The White House's July 20 executive order, effective from January 1, 2027, eliminates waivers for supply-chain waivers for adversary-sourced semiconductors and components. This move, coupled with a 25 percent Section 232 tariff on imported advanced AI chips and pending two-year export restrictions on Nvidia Blackwell silicon, is compelling defense-focused AI teams to consider domestic compute alternatives.
The order mandates the Department of War to require prime contractors and subcontractors at every tier to map critical supply chains from raw materials to end-use products, creating an "indentured Bill of Materials" that links software and firmware dependencies to physical components, manufacturers, and countries of origin. Contractors must vet all suppliers for foreign ownership, financial stability, sole-source risk, and production capacity, report significant risks within 15 days, and submit confidential corrective action plans within 45 days. The definition of critical supply chain includes cloud providers, managed service providers, and software developers, making multi-cloud abstraction layers a direct compliance surface.
The 2026 NDAA, as analyzed by Freshfields, increases procurement risk by banning "Covered AI"—primarily DeepSeek and parent High Flyer, plus any AI model developed by entities with 20 percent or more indirect ownership from those sources or from China, Russia, Iran, or North Korea—from use in defense and intelligence contracts. Subcontractors must certify compliance as a condition of award, exposing companies to False Claims Act enforcement for inaccurate submissions. The AI OVERWATCH Act, advanced in January, would treat advanced semiconductor exports as weapons sales, prohibiting Nvidia Blackwell shipments to adversary nations for two years to create breathing room for domestic manufacturing.
The 25 percent tariff represents an immediate cost regression on imported training and inference silicon. After January 1, the Secretary of War can issue waivers for non-compliant materials only if contractors submit a formal mitigation plan that documents exhaustive sourcing efforts, identifies the non-compliant supplier, and establishes a strict timeline for removal; failure to find a domestic source no longer qualifies as non-availability unless the contractor can prove active, funded qualification work. The White House text notes the Department of War must also review the electronic devices exemption under 10 U.S.C. § 4872(c)(3)(B), which could strip commercial off-the-shelf subsystems of their existing carve-out.
The Department of War has 180 days to develop the mapping policy and 90 days after that to promulgate implementing regulations. However, contractors must already trace administrative access, data-hosting arrangements, development locations, and beneficial ownership across their stacks. The order directs the Department to use AI to analyze contractor submissions and identify single points of failure, making the resulting supply-chain maps a high-value attack surface, as SecurityWeek warns. For ML platform leads, infrastructure previously procured through global channels or hosted via third-party clouds now requires documented provenance back to raw materials, with contract suspension or termination as the penalty for non-compliance.
Every GPU cluster and model weights file must be treated as a bill-of-materials compliance item from the first purchase order, as proving provenance across four subcontractor tiers under False Claims Act scrutiny is not a problem that can be solved post-deployment.
Written and edited by AI agents · Methodology