Unbreakable Ventures
Unbreakable Ventures
Chip Cartel | Risk Updates for Weeks of August 27 and September 9, ‘26
0:00
-15:43

Chip Cartel | Risk Updates for Weeks of August 27 and September 9, ‘26

Threat concerns this fortnight: Fifteen countries control nine in ten AI exports. Why the US military switched off its ad trackers. And five quick fires on gas, food and spam at scale.

Hello 👋 get a brew on because these are the top emerging risks between August 26th, and September 9th, 2026…

Review our report’s terminology here ↗

Our main risk this fortnight is…

1. Economic: AI Supply Chain Concentration Risk Deepens

  • Trade credit insurer Atradius finds AI-enabling goods trade is extraordinarily concentrated, with the 15 largest exporters accounting for 85 to 90 percent of global exports across every major segment of the chain.

  • Asian economies supply 65 percent of measured AI-enabling exports. China leads, followed by Hong Kong, Taiwan and the United States, with Singapore, South Korea, Germany and the Netherlands also central.

  • Exposure is asymmetric. AI-enabling goods represent 65 percent of Taiwan’s total exports and 56 percent of Hong Kong’s, meaning any disruption to those two economies transmits directly into global compute capacity.

  • Firm-level chokepoints compound the country risk. Nvidia holds over 80 percent of data centre GPU design, TSMC fabricates most advanced AI chips, and those fabs depend on ASML lithography equipment.

  • Atradius warns Europe sits weakly positioned between an Asia dominating chip production and rare earth exports, and a United States controlling software, cloud infrastructure and chip design.

Sources

You should be concerned if…

  • You are a European manufacturer or industrial buyer: Atradius places Europe between Asian chip and rare earth supply and American design and cloud control. Firms there hold limited leverage when either bloc restricts flows for policy reasons.

  • You operate in or source from Taiwan and Hong Kong: With AI-enabling goods at 65 and 56 percent of exports respectively, both economies carry outsized exposure. Disruption there hits your input costs, lead times and counterparty solvency simultaneously.

  • You are procuring data centre capacity or AI hardware: Concentration at Nvidia in GPU design, TSMC in fabrication and ASML in lithography means alternative suppliers do not meaningfully exist. Allocation, not price, becomes the binding constraint on expansion.

  • You depend on rare earths and critical minerals: Chinese export controls have widened during 2026 through firm-level restrictions targeting American and European companies. Downstream buyers who never tracked mining exposure now face licensing delays they cannot influence.

  • You are an insurer, lender or trade credit provider: Portfolio exposure across electronics, logistics and technology clients may correlate far more tightly than segment classification suggests, because the same handful of exporters and firms underpin all of them.

  • You run logistics through East Asian ports and corridors: Atradius flags shipping delays alongside tariffs and export controls. Concentrated origin points mean congestion or closure at a small number of nodes propagates across unrelated customer sectors.

These items are generic assumptions. We recommend considering your own unique risk landscape against your critical dependencies. If you don’t know what they are, get in touch.

Preventative actions

Map your chain to component and country of origin
  • Trace critical inputs beyond your tier one supplier to the fabrication site, equipment vendor and mineral source. Record the specific chokepoint firms and jurisdictions you depend on, then refresh the map quarterly.

Model an export control shock, not a supplier failure
  • Run a scenario in which a government, not a vendor, halts a flow you rely on. Test how long production continues, which contracts breach first, and what licensing evidence you would need.

Build allocation agreements ahead of scarcity
  • Negotiate committed volumes, priority positions and forward pricing with hardware and component suppliers now. Where allocation cannot be secured, document a qualified alternative architecture that tolerates older or lower specification parts.

Hold strategic buffer stock on genuinely scarce inputs
  • Set inventory cover by chokepoint severity rather than uniform policy. Inputs with a single global supplier or a single national source warrant materially deeper buffers than commodity parts with many origins.

Reassess counterparty and credit concentration
  • Review whether customers, suppliers and insured risks cluster around the same exporting economies. Set concentration limits by origin jurisdiction and monitor trade policy announcements as a credit signal, not just a compliance matter.

Diversify compute geography and contract terms
  • Where cloud or AI workloads are critical, split them across providers and regions, and secure contractual portability of data and models so capacity constraints in one jurisdiction do not halt delivery.


2. Technological: Ad Trackers Became Military Targeting Data

  • US military officials say they have disabled advertising trackers on a range of phones and computers, in letters released by Senator Ron Wyden, after reports that commercially available location data had been used to target American forces in the Middle East. Wyden says the effort has not been effective at neutralising the threat.

  • US Central Command told Congress in April it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil personnel in theatre during Operation Epic Fury.

  • Disclosures came through letters released by Senator Ron Wyden. Senator Heinrich’s office described it as the first confirmation that adversaries are using commercial location data against American servicemembers in an active war zone.

  • The data path is ordinary. Apps collect location, share it with third parties and brokers, and it is then sold on the open commercial market to any buyer willing to pay.

  • Earlier reporting had already shown brokered data tracking devices to and from military installations in Germany, and Strava and Polar fitness apps exposing base locations and personnel routes.

Sources

You should be concerned if…

  • You employ executives or staff who travel to high risk regions: The same advertising identifiers that exposed troop movements sit on corporate handsets. Pattern of life data reveals hotels, routes and meeting locations to anyone able to purchase a dataset.

  • You operate critical national infrastructure sites: Energy, water, telecoms and transport facilities can be identified through clustered device activity. Staff commuting patterns effectively publish shift changes, control room occupancy and access points without any insider involvement.

  • You are in defence, aerospace or government supply chains: Contractor personnel are not covered by military device policies. Adversaries mapping a programme may find its people through supplier employees rather than through the primary contracting organisation.

  • You run corporate security or executive protection: Threat models built around physical surveillance underestimate a purchasing route. Commercial datasets deliver historical movement at scale, cheaply, remotely and without the risk of a follower being detected.

  • You handle mergers, litigation or sensitive negotiations: Location data reveals who met whom and where, well before any announcement. Competitors and activist investors can buy behavioural signals that no confidentiality agreement covers.

  • You build or monetise mobile applications: Location sharing embedded in advertising software development kits is now demonstrably a national security issue. Regulatory and contractual pressure on onward data sale is likely to increase for publishers.

Preventative actions

Disable advertising identifiers across the managed device estate
  • Enforce advertising ID resets and removal through mobile device management on all corporate phones, tablets and laptops. Verify the setting persists after operating system updates and cannot be re-enabled by users.

Restrict location permissions by policy, not by request
  • Block location access for all applications by default and grant exceptions individually with a documented business justification. Review the exception list quarterly and revoke permissions for applications no longer in operational use.

Publish a travel device standard for high risk destinations
  • Issue clean loan devices for travel to sensitive regions, with minimal applications, no personal accounts and no location services. Wipe and reimage on return before the device rejoins the corporate network.

Buy your own exposure and see what surfaces
  • Commission a controlled assessment that attempts to purchase commercially available data relating to your sites and personnel. Use the findings to quantify real exposure rather than relying on assumed privacy protections.

Write data onward sale restrictions into supplier contracts
  • Require application vendors, marketing partners and telematics providers to disclose every third party receiving location or device data, and prohibit resale to brokers. Include audit rights and termination triggers for breach.

Brief personal device behaviour for staff at sensitive sites
  • Train employees on fitness apps, delivery apps and social features that publish routes and check ins. Establish a rule that personal accounts never record activity within site perimeters or during operational deployments.


Risk Flow Graph

Using the data from our flagship AI powered threat intelligence tool*, we can see trends of events per threat category over time. This fortnight, the biggest increase in risks concerns (1) Technological; 98 stories, (2) Geopolitical; 94 stories, (3) Economic; 59 stories, (4) Environmental; 48 stories, (5) Societal; 26 stories.

*Fx.AI is exclusive to Fixinc clients. Contact us to learn more.

Quick snippet stories

  1. ASCII smuggling moves from AI attacks to spam at scale
    A technique for hiding instructions inside invisible Unicode characters, once used to slip prompt injections past human reviewers, is now being used to defeat email security filters. Microsoft observed detections climbing from roughly twenty one thousand daily into the millions within days. Enforce Unicode normalisation at the mail gateway and test filters against invisible character payloads.
    Main link to resource ↗

  2. Singapore firms move toward cyber insurance as AI threats reported
    An ESET commissioned survey of Singapore cybersecurity decision makers, run by Blackbox Research, reports widespread experience of AI assisted threats including deepfake and voice cloning attacks. These are self reported figures from a vendor sponsored study, not verified incident data. Treat insurance as a complement to controls, and implement callback verification for all payment instruction changes.
    Main link to resource ↗

  3. Watchdog flags gaps in UK food supply resilience
    The National Audit Office warns that Britain’s food supply chain faces mounting exposure to extreme weather, cyberattacks and wider disruption, while government coordination and household preparedness lag behind the threat. Concentration in processing and distribution amplifies single points of failure. Map your food and packaging suppliers to physical sites, and pre-qualify alternates outside affected weather and logistics corridors.
    Main link to resource ↗

  4. Germany enters winter with thin gas storage and firm prices
    Germany faces the heating season with historically low storage while geopolitical disruption lifts European gas prices, pressuring industrial output and a fragile recovery. The energy regulator currently rates the chance of an actual supply shortfall as low, so the exposure is price and volatility rather than certain shortage. Hedge energy costs forward and model production at sustained elevated prices.
    Main link to resource ↗

  5. Airport breach exposes contact details, vehicle registrations and parking records
    Criminals have published data on nearly nine million people taken from Manchester Airports Group, covering Manchester, London Stansted and East Midlands, after an extortion attempt failed. Contact details, vehicle registrations and postcodes were taken from wi-fi login and car parking databases, and the full set is now being offered free to other criminals, so secondary fraud is the live risk rather than the original breach. Minimise retention of booking records and treat any customer wi-fi or parking database as PII, not convenience data.
    Main link to resource ↗

More stories we’re following

Here are more threat updates we’re monitoring across the month listed for your convenience.

  • X users targeted by mass password reset attacks following X Money launch Link ↗

  • Pentagon official reaffirms Anthropic blacklist despite Commerce Secretary's comments Link ↗

  • Global food prices hit two-year high as weather, war, conflict converge Link ↗

  • Extreme weather, geopolitical chaos, and GPS jamming compound maritime disruption risk Link ↗

  • Bangladesh textile industry hobbled by chronic energy crisis, output slumps Link ↗

  • China rare earth export curbs threaten India’s EV manufacturing localisation timeline Link ↗

  • AI data centre boom concentrates billions in assets in disaster and terrorism hotspots Link ↗

  • Microsoft-backed AI data center accused of operating dozens of unpermitted generators in New Jersey Link ↗

  • Unimicron probed for relabeling Chinese PCBs as Taiwan-made AI chip materials Link ↗

  • Sony and Warner sue Anthropic over alleged theft of musical works Link ↗

  • Bangladesh fertiliser shortages worsen ahead of critical Boro season despite adequate national stocks Link ↗

  • Executive order lets Energy Secretary restrict foreign power grid equipment over cyber and supply chain risks Link ↗

  • Australian businesses dramatically underestimate cyber recovery times, creating operational blind spots Link ↗

  • AI-accelerated vulnerability discovery tops global corporate risk concerns Link ↗

  • Canada’s AI-driven data centre boom poses untested infrastructure resilience risks Link ↗


Want to discuss how these risks might effect your business?
Book 30 minutes with us, free ↗

Every fortnight, we send out a risk you may not have heard to help you stay prepared. You can always unsubscribe later.


Need support?

At Fixinc, we are passionate about helping people get through disasters. That’s why our team of Advisors bring you this resource free of charge. If you need help understanding these threats and building a plan against them, the same Advisors are here to help over a 30-minute online call. Once complete, if you like what was provided, you can choose to provide a donation or subscribe to Unbreakable Ventures to support this channel.

Book your 30min call here

Help us help people just like you. Share this post today and spread the support 🤝

Share

Discussion about this episode

User's avatar

Ready for more?