Invest1 distinct publisher3 min readUpdated
US export controls cover physical Nvidia chips, not remote access to them. A House-passed bill would change that, but the rule-writing and the customer checks are still unfinished business.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
A White House official has publicly accused a Chinese AI lab of using Nvidia's restricted GB300 chips through a data center in Thailand, and the bill written to stop that is sitting in the Senate [3][12]. The gap matters because the US export control regime was built around hardware crossing a border, and this trade does not require the hardware to move.
Less than a week after Moonshot AI released a new model in July, White House official Michael Kratsios accused the company of tapping GB300s via a Thai facility [3]. Nvidia's most advanced AI chips are barred from export to China, while less capable parts are still allowed [1]. Moonshot's Kimi K3 is one of several recent Chinese models, alongside new systems from DeepSeek and Alibaba, that have scored well on performance benchmarks [4][5].
The awkward part for Washington is that the arrangement described may be lawful. Cassia King, senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy, told CNBC that Moonshot's reported access through a Thai facility was legal "so long as Moonshot isn't actually buying and owning the physical hardware directly," because the regime "controls physical AI chips. It does not cover remote access to those chips" [6][7]. A White House official told CNBC the administration "has implemented the most rigorous export control regime in modern history" and remains committed to safeguarding national and economic security [8]. The Commerce Department and the Bureau of Industry and Security did not respond to CNBC's request for comment [9].
The pattern is not one lab. Chinese hyperscalers including ByteDance, Alibaba and Tencent have reportedly accessed Nvidia compute remotely via Thailand, Malaysia and Japan [10]. ByteDance was working with Singapore-headquartered cloud provider Aolani to reach compute in Malaysia, according to a source familiar with the matter cited by CNBC, an arrangement the Wall Street Journal first reported in March [11]. Aolani told CNBC its customers "do not have ownership, potential future claim or physical access to the chips that power our solutions" and that access to its services is fully compliant with applicable regulations [13].
The supply of places to do this is growing quickly. DC Byte data shows 31 planned data centers of 100MW or larger across Malaysia, Indonesia and Thailand, against two today, roughly a fifteenfold increase in sites at that scale [14][15]. JLL estimates global data center capacity could roughly double to 200GW by 2030, implying about 100GW now [16][17]. Michelle Nie, a visiting fellow at the Center for a New American Security, told CNBC the loophole was "threatening U.S. national security," since the point of chip controls "is to deny China the ability to train frontier AI using advanced U.S. chips" [18][19].
The Remote Access Security Act would extend export controls to remote cloud access of controlled hardware and software. It passed the House in January and has not passed the Senate [12]. Nie cautioned that passage alone would not fix the problem: it grants the authority to regulate remote access, after which the government still has to write a rule actually controlling it [21]. Cloud providers would carry the compliance burden of any know-your-customer and verification requirements, which invites industry pushback [20].
Watch three things: whether RASA clears the Senate, whether BIS follows with an actual rule rather than authority on paper, and how fast those 31 planned sites come online relative to any verification regime [12][21][14].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Despite US restrictions on exporting Nvidia's most advanced semiconductors, including GB300s, several Chinese firms have reportedly been able to access the chips' compute power via data centers in Southeast Asia.
Chinese hyperscalers including ByteDance, Alibaba and Tencent have reportedly accessed compute power from Nvidia chips remotely via other Asian nations, including Thailand, Malaysia and Japan; ByteDance and Tencent did not respond to CNBC's request for comment and Alibaba declined to comment.
Nvidia's most advanced AI chips are under US export restrictions to China, though some less capable semiconductors are allowed to be shipped to the country.
Less than a week after Moonshot AI released a new model in July, White House official Michael Kratsios accused the company of using Nvidia's GB300 chips via a facility in Thailand.
Moonshot's Kimi K3 is one of a wave of new Chinese AI models that have made leaps in performance in recent months.
DeepSeek and Alibaba have also recently released new AI systems that scored well on performance benchmarks.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named experts and on-record statements, but the core usage claims are single-outlet and partly anonymous
The legal mechanism, the RASA status, and the compliance burden are attributed to identified specialists (King of IAPS, Nie of CNAS) and supported by on-record White House and Aolani statements plus third-party data from DC Byte and JLL. The load-bearing behavioral claims - that specific Chinese firms trained on restricted Nvidia compute abroad - are hedged as 'reportedly', rest on one anonymous source for the ByteDance-Aolani arrangement, and are unconfirmed by the companies, with Commerce and BIS silent. Cluster has a single publisher, so no independent corroboration is present.
The loophole is in active use; the remedy has no adoption at all
On the practice side there is concrete adoption: multiple named Chinese firms reportedly renting restricted-class Nvidia compute through Thai, Malaysian and Japanese facilities, one specific provider relationship (ByteDance-Aolani), and a 31-site 100MW+ regional pipeline against two operating sites. On the policy side adoption is zero: RASA is House-passed but stalled in the Senate and no implementing export-control rule for remote access exists, so nothing in the story's proposed fix has been deployed. Volumes of compute actually consumed are not disclosed, which caps the score.
Framing of an imminent Washington fix runs ahead of a stalled bill and an unwritten rule
The story is presented as the U.S. 'trying to close' the loophole, and the cluster dek asserts a fix, while the reporting itself establishes that RASA has not passed the Senate, that a separate BIS rule would still be required, and that the hard parts - scope, prohibited parties, enforceable KYC - are undecided. The overstatement is modest rather than severe because CNBC carries those caveats explicitly and quotes both the authority gap and the pushback risk; the alleged Chinese usage is also consistently hedged rather than asserted as fact.
Strongly interested voices on every side: administration, security think tanks, cloud providers, Chinese users
The sourcing is dominated by parties with stakes in the outcome. A White House official defends the administration's record as 'the most rigorous export control regime in modern history'; two think-tank researchers whose remit is compute and national security policy argue the loophole threatens security and needs new rules; the cloud provider named in the story issues a compliance-affirming denial; and the Chinese firms whose access is alleged either declined or did not respond. Nie explicitly identifies cloud providers' financial interest in resisting KYC mandates. No party in the piece is disinterested, though positions are attributed openly rather than laundered.
Moderate: policy mechanics are solid, usage specifics and outcomes are not
Confidence is anchored by verifiable, checkable elements - the legal distinction between physical chips and remote access, RASA's House passage and Senate limbo, the identified experts, and cited third-party capacity data. It is limited by the single-publisher cluster, the hedged and partly anonymous usage reporting, the absence of any Commerce/BIS position, and the fact that the story's forward-looking claim (that Washington will close the loophole) depends on unfinished legislation and unwritten rules.
product
Nvidia's H200 finally lands in China at about 1% of the order book2 distinct publishers
build
1.5% of Hugging Face repos take 99.2% of downloads, and the ceiling is Chinese1 distinct publisher
product
Baidu's AI line grew 25 percent and still lost the arithmetic1 distinct publisher
build
China's accelerator swap makes Cambricon supply, not export policy, your ship-date risk1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026