Inspur Changed Its Name and Kept Buying Restricted AI Chips Anyway
What happened
In 2023, U.S. authorities added Inspur Group to the entity list, a move meant to cut off the Chinese server manufacturer from advanced American semiconductor technology. The designation targeted Inspur because of its scale, its government contracts, and its proximity to Chinese state interests. It did not take long for the company to find a way around it.
Inspur's U.S. subsidiary quietly rebranded as Aivres. Under that new corporate identity, the subsidiary continued placing orders for high-performance Nvidia chips and servers, hardware that remained off-limits to the parent company by name. The goods then moved through intermediaries in Southeast Asia before completing the journey to Chinese customers. Among those end recipients were firms with documented ties to China's military and defense sector, exactly the category of customer the original blacklisting was designed to exclude.
The scheme worked because export controls are structured around named entities and declared end-users. A subsidiary operating under a different name, acquiring goods in stages through third countries, can satisfy the paperwork requirements of each individual transaction while the cumulative effect violates the policy's intent entirely. Inspur remained on the list. Aivres was not. The hardware moved. The entity list is a designation, not a wall.
U.S. federal investigators opened inquiries once the pattern became visible. The case landed alongside a growing body of evidence that name-based sanctions are structurally vulnerable to corporate restructuring and geographic routing. Placing a name on a list stops the named entity from transacting directly. It does not stop an affiliated network from standing up a clean legal face, one that has not accumulated a compliance history, and using it to resume the same purchases through the same channels at the same scale.
The Inspur case is ultimately an evidentiary problem as much as a legal one. Regulators can examine individual transactions, but connecting them into a pattern, tracing hardware from a U.S. supplier through a rebranded subsidiary through a Southeast Asian intermediary to a restricted end-user, requires records that are rarely complete, rarely standardized, and rarely held by any single authority. A provable record of what a system did, who received it at each step, and what the declared end-use actually was, is precisely the infrastructure that would make this kind of evasion visible before an investigation rather than as its conclusion.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.