Texas AG Proposes Federal Ban on Chinese Tech in Data Centers, Criminal Liability for Harmful AI

CryptoStack Investment Research

Hook

Texas Attorney General Ken Paxton has proposed a federal ban on Chinese technology within U.S. data centers, coupled with criminal liability for harmful AI systems. The proposal, if enacted, would fundamentally restructure the operational landscape for every data center operator and AI developer in the country. The ledger does not lie, only the interpreters do—and this ledger reads as a tectonic shift in how Washington approaches both technological supply chains and algorithmic accountability.

Context

The proposal arrives amid escalating U.S.-China technology tensions and a broader push by state-level officials to shape federal policy. Paxton, a Republican known for aggressive legal maneuvers against the Biden administration on immigration and tech regulation, is now targeting the technology supply chain itself. His office has framed the measure as a national security imperative, arguing that Chinese hardware, software, and management services embedded in American data infrastructure represent potential backdoor vectors for espionage and sabotage.

The proposal carries two distinct components. First, a comprehensive ban on Chinese technology—spanning servers, chips, storage devices, operating systems, and virtualization platforms—within any data center operating on U.S. soil. Second, the establishment of criminal liability for developers and operators who deploy AI systems that produce "harmful" outcomes. The latter represents an unprecedented move to criminalize algorithmic behavior, elevating AI governance from civil and administrative oversight to the criminal code.

Core

The Legal Architecture: What This Actually Means

The proposal, if enacted, would likely route through the Export Administration Regulations (EAR), the International Emergency Economic Powers Act (IEEPA), and Title VII of the Defense Production Act. But here is the structural anomaly: a comprehensive data center ban on Chinese technology does not exist in current U.S. law. The existing framework operates through case-by-case restrictions—entity list designations, targeted export controls—not blanket prohibitions. This proposal would create an entirely new regulatory category.

Texas AG Proposes Federal Ban on Chinese Tech in Data Centers, Criminal Liability for Harmful AI

The IEEPA route is the critical variable. The statute allows the executive branch to impose economic sanctions without congressional approval, provided there is a declared national emergency. This is the fast lane around legislative gridlock. Trust is a bug, not a feature—and the legal architecture here reflects that distrust of both Chinese technology and the deliberative process itself.

But there is a structural vulnerability in the administrative route. The Supreme Court's West Virginia v. EPA decision (2022) established the Major Questions Doctrine, requiring clear congressional authorization for agency actions involving significant economic and political questions. A data center ban affecting hundreds of billions in infrastructure investment qualifies as a major question. An executive order implementation would face immediate legal challenge and likely be overturned. Congressional legislation, however, would be far more durable.

The "Harmful AI" Problem: A Definitional Vacuum

The criminal liability component presents an even more vexing problem. The proposal would create federal criminal exposure for AI systems deemed "harmful"—but the definition of "harmful" remains undefined. This is not a drafting oversight; it is a feature. The ambiguity creates a chilling effect across the industry. Code is law; intent is irrelevant. Under this framework, an AI developer could face criminal prosecution for algorithmic outputs they never anticipated.

The enforcement framework would likely mirror the Computer Fraud and Abuse Act (CFAA) structure: fines up to $1 million for individuals, $100 million for corporations, and imprisonment up to 20 years. But the CFAA analogy breaks down in one critical respect: CFAA requires intent. A strict liability standard for AI harm—criminal liability without proof of intent or negligence—would transform the AI industry overnight. Every model deployment becomes a potential criminal act.

The Supply Chain Compliance Trap

For data center operators, the compliance burden would be immediate and severe. The "Chinese technology" definition is the core uncertainty. Does it cover chips designed in the U.S. but fabricated in Taiwan with Chinese components? Does it apply to open-source software with Chinese contributors? The ambiguity creates a compliance trap: operators cannot certify compliance with undefined standards.

Based on my audit experience, I can identify the practical failure mode here. Enterprise supply chains are not linear; they are recursive graphs. A server manufactured in Malaysia contains components from thirty countries. A software stack includes libraries from hundreds of maintainers. Proving "no Chinese technology" anywhere in that graph is practically impossible—and criminal liability for failing to prove a negative creates untenable risk exposure.

The compliance cost projection is stark. Current compliance spending for data center operators runs 1-2% of revenue. A comprehensive supply chain certification regime, AI safety testing infrastructure, and legal defense preparedness would push that to 5-10%. For mid-sized operators, that is a survival question.

Contrarian

The bulls on this proposal have a point, and it deserves acknowledgment. The national security concern is not manufactured. Chinese technology in critical infrastructure does present genuine supply chain risk. The 2020 SolarWinds attack demonstrated how compromised software propagates through trusted networks. The 2021 Hafnium exploitation of Exchange servers showed the damage from state-aligned actors exploiting vulnerabilities in widely deployed technology.

The criminal liability framework, while crude, addresses a real governance gap. AI systems are increasingly autonomous and consequential. The current regulatory patchwork—voluntary commitments, state-level consumer protection actions, agency guidance—has not kept pace with deployment velocity. The proposal forces a serious conversation about accountability that the industry has been avoiding.

Takeaway

The proposal may never become law. But it is a signal. State-level officials are prepared to drive federal AI and technology policy through the national security frame, and criminal liability is now on the table as a governance tool. History repeats, but the gas fees change. The industry can adapt to regulation; it cannot adapt to undefined criminal exposure. The smart play is not to fight the direction of travel, but to demand definitional clarity. Otherwise, the chilling effect will do what no regulator has yet achieved: slow AI deployment to a crawl. The question is not whether this proposal passes—it is what shape the next iteration takes.