Skip to main content

World Reporter

Chinese AI Firms Access Restricted Nvidia Chips Through Southeast Asian Cloud Servers, Exposing a Structural Gap in U.S. Export Controls

Chinese AI Firms Access Restricted Nvidia Chips Through Southeast Asian Cloud Servers, Exposing a Structural Gap in U.S. Export Controls
Photo Credit: Unsplash.com

Chinese artificial intelligence companies including Moonshot AI, ByteDance, Alibaba, and Tencent have been accessing restricted Nvidia GPU computing power through data centers in Thailand, Malaysia, and Japan, exploiting a gap in U.S. export controls that governs the physical transfer of chips but does not extend to remote cloud access. The documented loophole has prompted a legislative push in Washington, where the Remote Access Security Act passed the House of Representatives in January 2026 and now awaits a Senate vote that could redefine how cloud computing intersects with national security law.

Key Takeaways

  • U.S. export controls restrict physical shipments of advanced AI chips to China under ECCN 3A090, but do not cover remote access to the same computing power through cloud services hosted outside China.
  • Chinese AI companies have reportedly rented compute from restricted Nvidia GPUs, including GB300 processors, through data centers in Thailand, Malaysia, and Japan.
  • The Remote Access Security Act (RASA) passed the U.S. House 369-22 in January 2026 and awaits a Senate vote; it would authorize the Bureau of Industry and Security to regulate remote access to controlled technology.
  • Even if RASA passes, a separate rulemaking process would be required before BIS could enforce restrictions on cloud-based access to specific chips.
  • The Institute for AI Policy and Strategy estimates that the minimum amount of compute China is accessing through the cloud loophole could boost the country’s total compute capacity by at least 60% in 2026.

The Export Control Framework Was Built for Physical Chips, Not Cloud Access

The foundation of Washington’s AI containment strategy rests on export controls under the Export Administration Regulations, specifically ECCN 3A090, which prohibits chips above a certain performance threshold from being shipped to designated countries including China. These controls were designed around physical transactions: manufacturing, shipping, and receiving hardware. But the modern AI industry increasingly operates through cloud infrastructure, where computing power is rented remotely rather than purchased and installed on-site.

The Bureau of Industry and Security, the Commerce Department agency responsible for enforcing export controls, has not interpreted its authority to cover cloud services as controllable items. Advisory opinions published by BIS dating back to 2009 have consistently drawn a line at the physical transfer of goods, leaving remote access to the same technology in a regulatory gray zone. That distinction means a Chinese AI company cannot legally import an Nvidia GB300 chip, but it can rent access to one housed in a data center in Bangkok and use it to train the same models the export controls were designed to prevent.

Cassia King, a senior researcher in the Compute Policy group at the Institute for AI Policy and Strategy, confirmed that the arrangement complies with existing rules. The current framework does not cover remote access to controlled chips, King noted, regardless of who is accessing them or what they are being used for.

Moonshot AI, DeepSeek, and Alibaba Are Producing Competitive Models

The loophole moved from a theoretical concern to a geopolitical flashpoint after a series of Chinese AI models demonstrated performance gains that industry observers linked to access to advanced compute. Moonshot AI released its Kimi K3 model in July 2026, prompting White House official Michael Kratsios to publicly accuse the company of using Nvidia’s GB300 chips through a facility in Thailand. DeepSeek and Alibaba have also released new AI systems in recent months that scored well on performance benchmarks, contributing to a wave of Chinese model capability that has narrowed the gap with leading U.S. systems.

The pattern has raised alarms across the U.S. national security establishment. The AI models being built by Chinese firms are not niche research projects. They are commercial products with applications in defense, intelligence, autonomous systems, and economic competitiveness. The concern is that U.S. export controls, which were intended to slow China’s progress in frontier AI, are being undermined by an infrastructure model that physically complies with the law while functionally delivering the same outcome the restrictions were designed to prevent.

CNBC reported that the firms in question are routing through data centers operated by cloud providers in Southeast Asia and Japan. These facilities house Nvidia’s restricted chips legally, purchased before or outside the scope of the export controls. Chinese companies then rent computing time on those servers, training and running models without any controlled hardware crossing a Chinese border.

RASA Passed the House With Overwhelming Bipartisan Support

The legislative response has coalesced around the Remote Access Security Act. The bill, designated H.R. 2683, was introduced by Representative Mike Lawler of New York in April 2025 and approved unanimously by the House Foreign Affairs Committee at 51-0 the same month. The full House passed RASA on January 12, 2026, by a vote of 369-22, a margin that reflects durable bipartisan support for closing the cloud loophole.

House Select Committee on China Chairman John Moolenaar, a co-sponsor, described the bill as bringing U.S. law into the digital age. Senator McCormick, a Senate co-sponsor, framed the legislation as closing a security gap that allows otherwise prohibited users to access advanced chips under U.S. jurisdiction without a license. A companion measure is pending in the Senate, where it has bipartisan sponsorship. Legal analysts have noted that RASA could advance as standalone legislation or be attached to a larger vehicle such as the National Defense Authorization Act for Fiscal Year 2027.

The bill would amend the Export Control Reform Act of 2018 to authorize BIS to regulate remote access by foreign persons to items subject to the Export Administration Regulations through internet or cloud services. The authority it would grant is broad, encompassing not just GPU access but potentially a wide range of controlled technologies. That breadth has drawn pushback from industry groups and some foreign governments, who argue that the scope could disrupt legitimate cloud computing operations and create compliance burdens for data centers and their customers globally.

Passage Alone Would Not Immediately Close the Gap

Even if the Senate passes RASA and the bill is signed into law, enforcement would not be immediate. The legislation authorizes BIS to regulate remote access but does not prescribe the specific rules. BIS would need to conduct a separate rulemaking process to determine which items would be subject to remote access restrictions, what license requirements would apply, and how review policies would function. That process could take months or longer, during which the current loophole would remain open.

The Institute for AI Policy and Strategy has estimated that the minimum compute China is accessing through the cloud loophole could increase the country’s total compute capacity by at least 60% in 2026, a figure that underscores the scale of the gap between the intent of U.S. export controls and their practical enforcement. The estimate suggests that cloud access is not a marginal supplement to China’s AI infrastructure but a structurally significant source of computing power that is shaping the trajectory of Chinese model development.

The broader question the loophole raises extends beyond the specifics of chip export policy. As computing increasingly moves from owned hardware to rented cloud capacity, the entire architecture of technology export controls, built around the physical movement of goods, faces a conceptual challenge. RASA represents the first serious legislative attempt to extend that architecture into a cloud-native world, but the gap between passing a law and building an enforceable regulatory framework around global cloud infrastructure remains substantial.

FAQs

Why Can Chinese AI Companies Access Restricted Nvidia Chips Through the Cloud?

U.S. export controls under ECCN 3A090 restrict the physical shipment of advanced AI chips to China but do not cover remote access to those chips through cloud computing services. The Bureau of Industry and Security has not interpreted its authority to include cloud services as controllable items, creating a gap that allows Chinese firms to rent computing time on restricted hardware housed in data centers outside China.

What Is the Remote Access Security Act?

RASA (H.R. 2683) is a bipartisan bill that would authorize the Commerce Department’s Bureau of Industry and Security to regulate remote access by foreign persons to items subject to U.S. export controls through internet or cloud services. The House passed the bill 369-22 in January 2026. A companion measure is pending in the Senate.

Would RASA Immediately Stop Chinese Companies from Accessing Nvidia Chips Remotely?

No. RASA authorizes BIS to regulate remote access but does not prescribe specific rules. After enactment, BIS would need to conduct a rulemaking process to define which items are covered, what license requirements apply, and how reviews would be conducted. That process could take months, during which the current loophole would remain in effect.

World Reporter

Bringing the World to Your Doorstep: World Reporter.