At least there's some originality there.
As far as how, there are dozens of things companies could do. Require a credit card verification, don’t allow digital credit cards, don’t ship to PO Boxes, don’t allow VOIP phone numbers, require an account with the retailer, do browser/machine fingerprinting, don’t allow purchasing on a VPN, scan the secondhand market for barcodes and ban people, require linking social media accounts and check for matches, don’t allow different billing and shipping addresses, require phone number verification, and on and on and on.
If retailers wanted to make sure it was one customer per video card, they could absolutely, trivially, do it.
But why would they? That’s a lot of commotion, and things people would probably get upset about. It will lead to less traffic on their site. And, at absolute best, they will get the exact same revenue.
I don't think that sort of relationship between manufacturers and libraries exists, though, and I'm not sure it should.
A year from now nvidia will have new GPUs and the 3000 series will be relatively easy to buy.