Export control is a law about moving objects, and nothing here is an object

Here's the deal: CNBC reported on August 19 that the enforcement arm of the Commerce Department's Bureau of Industry and Security is examining how Chinese AI firms access Nvidia hardware overseas.

The word "access" is doing the work. For years, US semiconductor controls aimed at China have focused on stopping chips from physically crossing borders. Top-tier parts like Blackwell can't go to China. Lower-tier parts like the H200 are cleared conditionally.

But the current rules don't address remote access. Renting top GPUs by the hour in a data center in Thailand or Malaysia is entirely legal today. The chips never leave Thailand; what crosses the border is an SSH session and some data.

That matters because training a large model doesn't require owning chips. It requires using them for weeks or months. The goal of the controls was to keep China from building frontier models with cutting-edge compute; the object of the controls was the transfer of chip ownership. The gap between goal and instrument is what's now visible.

Put numbers on it. Training a frontier-class model means running thousands of top GPUs for weeks to months. Buying that costs billions, needs US approval, and requires physically landing the hardware in China. Renting it takes a contract. The hourly rate is higher than ownership, but when training finishes you only need to carry out the model weights — and weights are a file. Export controls don't stop files.

That's the crux. What the rules meant to block was Chinese frontier model development. What they actually controlled was the physical location of chips. And what building a model requires is not chip location but chip hours.

Who's involved — BIS, Moonshot AI, and the entities in between

BIS is the Commerce Department's export control enforcement agency, and it's currently mapping two categories: countries running black markets for physically smuggled chips, and countries where Chinese firms access chips remotely under legal cloud arrangements. The second isn't illegal at present. What BIS is doing looks less like enforcement and more like reconnaissance.

Moonshot AI lit the fuse. In July it released Kimi K3, which scored nearly as high on benchmarks as the latest systems from Anthropic and OpenAI. The question of how a Chinese firm reached that level without leading-edge chips came immediately, and White House official Michael Kratsios accused Moonshot of remotely accessing Nvidia GB300 chips through a facility in Thailand.

Alibaba's route is more layered. It reportedly uses Nvidia chips in Malaysia through intermediaries, with a Singaporean firm called Megaspeed in the middle and a Cayman Islands entity controlling the Singapore shell. On paper: US chips, in a data center in a US-approved country, rented by a Singaporean company. Nothing illegal anywhere in the chain.

ByteDance and Tencent have also been reported to reach restricted compute through data centers in Thailand, Malaysia, Japan and elsewhere.

Japan on that list is worth pausing on. Thailand, Malaysia and Singapore get described as regulatory gray zones, but Japan is a core US ally and an export-control partner. That the same structure works through a Japanese data center says this isn't a problem of lax oversight in particular countries — it's a design problem in the rules themselves. No amount of smuggling enforcement closes it.

What actually happened — how the gap opened

Date Event
2026-01-12 House passes the Remote Access Security Act (H.R.2683) 369–22; referred to Senate Banking
2026-06-01 US clarifies that the AI chip export ban applies to Chinese firms outside China
2026-07 Moonshot AI releases Kimi K3; Kratsios points to GB300 access via Thailand
2026-08-19 CNBC reports BIS enforcement reviewing remote access routes

Note that the US already tightened one layer on June 1, clarifying that a Chinese company setting up an offshore entity to buy chips is also prohibited. But that's still a rule about purchase. Renting remained untouched.

Congress saw this coming much earlier. The Remote Access Security Act (RASA) would amend the Export Control Reform Act of 2018 to authorize extending export controls to remote access. It defines the term as access by a foreign person to an item subject to the EAR "through a network connection, including the internet or a cloud computing service, from a location other than where the item is physically located."

The House passed it 369 to 22 on January 12. In the current US Congress, that margin is effectively unanimous. And yet the Senate hasn't moved in eight months — the bill sits in the Senate Banking, Housing and Urban Affairs Committee.

So the situation is: the problem is known, the fix has bipartisan agreement, the House passed it, and BIS is doing surveys because there's no law. Meanwhile the scale has grown. Reporting indicates Chinese firms reached more than 2,300 restricted Blackwell GPUs through offshore rental arrangements.

Who profits from this structure

Chinese AI firms buy time. They need compute now to stay in the frontier race while domestic silicon such as Huawei's Ascend matures. Renting costs more than owning but is far faster and politically quieter. Kimi K3 demonstrated the strategy works.

Southeast Asian data center operators are the clearest winners. Thailand, Malaysia and Singapore attracted heavy AI data center investment over the past three years on cheap power, favorable tax treatment, and eligibility for US export approval. Chinese demand added a premium customer tier on top.

Nvidia sits awkwardly. The chips were sold to approved operators in approved countries. Who those operators rent hours to is outside Nvidia's control. It's legal and it helps revenue, but the political pressure keeps building. The company's worst case is controls extending to remote access with end-user verification obligations landing on the chip seller.

The intermediary entities are where the real margin lives. Singapore subsidiaries and Cayman holding structures don't appear by accident. Standing just outside a regulatory boundary and connecting both sides is the business model, and complexity in the rules widens the spread.

US cloud providers aren't clear of this either. If controls extend to remote access, KYC obligations spread across cloud contracts generally. "Who is actually using our GPUs" has been a commercial question; it becomes an export compliance question. Compliance cost rises structurally.

Even inside the US government the position isn't unified. The national security side wants broader controls; the trade side worries about US revenue and friction with allies. Remote access controls in particular put direct burden on allied data center operators, requiring negotiation with Thailand, Malaysia and Singapore. That friction cost is part of why the administration has hesitated to push this through rule interpretation alone.

Precedents — control and circumvention, repeatedly

Crypto export controls in the 1990s are the best-known case. The US classified strong encryption as a munition, and it was circumvented by printing source code in books and posting it on foreign servers. The controls lost effectiveness and were substantially relaxed in 2000. The lesson: you cannot stop something copyable and transmittable with a physical border. Remote access is the same class of problem.

Huawei sanctions from 2019–2022 cut the other way. The US initially blocked direct exports; when workarounds surfaced, it introduced the Foreign Direct Product Rule, which captures products made anywhere using US technology or equipment. That materially blocked Huawei's leading-edge chip supply. The lesson there: moving the object of control from the goods to the relationship makes it work. That's exactly the move RASA is attempting.

Multilateral coordination on semiconductor equipment controls from 2022–2024 is also instructive. Unilateral US controls were limited while ASML and Japanese toolmakers could fill the gaps; effectiveness jumped once the Netherlands and Japan joined. Remote access has the same shape — control only in the US and Chinese firms shift to infrastructure with less US content. Top-tier AI chips are effectively an Nvidia monopoly, though, which gives the US more leverage here than in tooling.

Parallel-import controls on Russia since 2022 are closer to a failure. The US and EU blocked semiconductor exports, but substantial volume kept flowing through third countries. It showed how hard physical smuggling is to stop entirely, and it's why BIS is mapping smuggling markets as a separate track.

How the players counter

Chinese firms are hedging on two tracks: keep pushing training through the current rental structure, and migrate toward domestic silicon ecosystems like Huawei Ascend. If RASA passes, the first path closes, and it becomes a race between regulatory speed and domestic chip maturity.

Nvidia's position is delicate. The company has repeatedly argued publicly that export controls mainly erode US market share and accelerate Chinese domestic development. Extending controls to remote access would hit Southeast Asian data center demand directly, so its incentive to oppose is unambiguous.

Southeast Asian governments have to balance US pressure against Chinese demand. If remote access controls arrive, their operators inherit customer screening obligations, and rising compliance cost undermines the low-cost structure that made those countries attractive in the first place.

US AI labs are quiet stakeholders. Chinese labs continuing to ship frontier-class models raises competitive pressure, and open weights affect commercial model pricing. But publicly demanding tighter controls is uncomfortable — what they sell is also access to compute.

Congress holds the next move. If Senate Banking schedules it, RASA has a strong chance. A 369–22 House vote on a rare bipartisan issue means the obstacle is calendar and priority, not opposition.

What actually changes for you

If you sell cloud GPUs, start reworking customer screening. Once remote access falls under the EAR, you inherit an obligation to know who is actually using an instance. Ultimate beneficial owner verification, no-resale clauses and access-region logging are likely to become contract standards.

If you use overseas data centers, check the ownership structure of the infrastructure you're on. If controls expand, your provider could land under sanctions review and force a workload migration. That's operational risk, not just geopolitical risk.

If you're in Korea or a similar jurisdiction, this isn't somebody else's problem. Domestic cloud and IDC operators are building rental businesses on large fleets of top-tier Nvidia GPUs. If remote access becomes an EAR-controlled activity, end-user verification obligations can reach them too, because jurisdiction follows the US-origin technology in the hardware. Keeping customer diligence records now is far cheaper than reconstructing them later.

If you invest in AI infrastructure, consider a regulatory discount on Southeast Asian data center assets. A meaningful share of current valuation there assumes Chinese demand. RASA passing puts that assumption in question.

If you own compliance, this is the moment to prepare. A bill that cleared the House 369–22 is unlikely to sit in the Senate forever, implementation windows tend to be short, and you may need to unwind existing contracts retroactively.

If you work in AI, note the underlying question. Is access to compute a good or a service? Export control frameworks were built over fifty years on the assumption of goods. In the AI era, most of what regulators want to control isn't a good. This is the first real case of that framework being rewritten for a new object.

🥄 Three Things You're Probably Wondering

— Is what they're doing illegal or not? Remote access itself isn't illegal under current law, and what BIS is doing looks more like fact-finding than enforcement. If a specific case also involves physically smuggled chips or false end-user declarations, that is separately illegal. The two are happening in the same regions, which blurs the line.

— When does RASA pass? Unknown. The House vote was in January and the Senate hasn't moved past committee. Given the margin, this reads as a scheduling problem rather than opposition. A Senate Banking markup being calendared is the earliest real signal.

— Would closing it even work? Partly. Top-tier AI chips are effectively an Nvidia monopoly, which gives the US strong leverage. But the useful life of any control depends on how fast Chinese domestic silicon matures and how quickly infrastructure with low US content appears. How long the controls stay effective is not something you can call today.

Sources

Numbers and criteria are as of announcement and may change.