4 min read
Checkbox Supply Chain Compliance Just Got a Lot More Expensive
Kelly Barner : July 30, 2026
For most of the last two decades, supply chain compliance has worked the same way: screen your supplier against a sanctions list, confirm the paperwork, check the box. That approach assumed something that's no longer true: a stable, rules-based international order where the rules held still long enough for a one-time check to mean something.
In this episode of Art of Supply, I speak with Elisar Nurmagambet, Co-Founder and CEO of Tesari AI, and Brian Andersen, Tesari's VP of National Security Applications, about what's replaced that model, and why it looks a lot more like investigative work than traditional compliance.
Elisar Nurmagambet started his career in financial crime investigation before founding a special-investigations firm focused on denied regions like Russia, China, and Central Asia. His work included COVID-era PPP and EIDL fraud investigations and sanctions evasion mapping. About a year ago, he founded Tesari AI to help companies understand who they're really doing business with in hard-to-reach jurisdictions.
Brian Andersen spent 20 years at Homeland Security Investigations' Global Trade Division, most recently helping stand up a unit focused on protecting U.S. supply chain interests for the Department of Defense. Listeners may recognize him from episode 211, "National Security Starts in the Supply Chain," recorded while he still held the title of Supervisory Special Agent. He now applies the same investigative mindset at Tesari AI.
The regulatory shift behind the shift in mindset
Both guests point to the same underlying cause: the U.S. government has been shifting the burden of national security compliance onto the private sector. In June 2026, Bosch became the first company to receive a declination under the Department of Justice's new, department-wide Corporate Enforcement Policy (CEP), but only after paying $36.2 Million to the Bureau of Industry and Security to resolve unlicensed exports of MEMS sensors and automotive software to Huawei, worth roughly $72 Million, and disgorging its profits from the sales. Under the CEP, a company that voluntarily discloses a violation and can show its work may avoid prosecution, although the CEO and other executives aren't shielded automatically, and the company still pays.
China has its own version of this shift. Decrees 834 and 835, which took effect in the spring of 2026, give Chinese regulators new tools to investigate and penalize foreign companies that disrupt supply to Chinese counterparties or comply with foreign sanctions in ways China considers discriminatory. The result, according to Elisar, is a genuinely bifurcated regulatory environment: a single transaction can be compliant under U.S. rules and a violation under Chinese ones, or vice versa.
From "checkbox" to investigation
Brian describes a recurring pattern from his years working with corporate compliance teams: trade, procurement, and national security tend to be treated as separate disciplines, each somebody else's job.
He argues that mindset no longer holds up, and that companies now need something closer to an investigator's approach: starting from a single piece of information (a shipment, a transaction, an entity) and building outward. Where did the goods come from? Who handled them? What else does that counterparty own or control? Each answer either resolves the question or raises the next one, until there's enough of a picture to make a defensible decision.
Elisar frames the same shift from the compliance side: understanding a counterparty is no longer enough. Companies now need to understand their counterparty's counterparty, across both the inbound and outbound sides of their supply chain.
A real example: the Meta-Manus deal
Elisar pointed to Meta's attempted acquisition of Manus, a Chinese-born AI agent startup, as a case in point. Meta closed the roughly $2 Billion deal in December of 2025. Four months later, China's National Development and Reform Commission blocked the acquisition and ordered it unwound, following a review that began with a U.S. Treasury investigation into Benchmark, the venture firm that had backed Manus's Chinese parent company, Butterfly Effect.
According to Elisar, Tesari AI flagged the deal to Meta four months before it collapsed. What his platform surfaced went beyond standard registry data (a company name, an address, a director). Manus's parent also built Monica, a separate product built for the domestic Chinese market, which Elisar says is used widely by Chinese government agencies and state companies. This is a critical detail because it recasts the underlying technology as sensitive by Beijing's own standard, even though Manus itself was positioned for export.
Tesari AI also flagged a Chinese commentator publicly suggesting the Ministry of Commerce could move to block the deal. Elisar point: in China, public commentary on a regulatory matter requires a government-issued license, so a seemingly offhand post was, in effect, an early signal of the ministry's own thinking.
Substance over form
Both guests returned to a related idea: legal registration doesn't determine jurisdiction the way it used to. A company can be incorporated in the Cayman Islands or Singapore, but if its engineering, manufacturing, or intellectual property is substantively based in mainland China (or Russia, Iran, or elsewhere) that underlying jurisdiction can still apply. Chinese officials reportedly describe this as a "substance over form" framework, and it underlies the country's approach to Decrees 834 and 835 as well as its outbound investment rules.
Where AI fits — and where it doesn't
Elisar was clear that Tesari sees AI as a tool for gathering and organizing information, not for making the final call. In his view, responsibility can't be outsourced to a model: a compliance officer, investigator, or national security analyst who signs off on a bad decision is the one who bears the consequences, so the decision has to stay human.
What AI can do, he said, is compress work that used to take months into a much shorter window, giving human decision-makers more complete information faster.
Lessons for procurement and supply chain leaders
- Screening a direct counterparty is no longer sufficient. Understanding who that counterparty does business with (its own suppliers, investors, and affiliates) is increasingly part of the job.
- Document the process, not just the outcome. Under frameworks like the DOJ's Corporate Enforcement Policy, being able to show what you asked, who you talked to, and what you found can be the difference between a penalty and a declination.
- Legal registration alone doesn't determine which country's laws apply to a transaction or an asset. Where the engineering, manufacturing, or IP actually resides matters more than where the entity is incorporated.
- Treat regulatory and reputational risk as a moving target, not a one-time check. A counterparty that's compliant today can become a liability as new rules take effect.
- AI tools can meaningfully speed up research and context-gathering across jurisdictions, but the decision about what to do with that information still needs a human owner.

