The Loophole Letting China Train AI on Banned Nvidia Chips

August 19, 2026

Summary: US export controls bar Nvidia's most advanced chips, including the GB300, from shipping to China, but Chinese firms including Moonshot AI, ByteDance, Alibaba and Tencent have reportedly accessed that same compute power remotely through cloud providers in Thailand, Malaysia and Japan, a legal gap since current rules restrict physical chip ownership rather than remote access. Legislation called the Remote Access Security Act has passed the House but stalled in the Senate, and experts say even its passage wouldn't close the loophole without a follow-up regulatory rule that's still undefined.

nvidiaexportcontrolschinaairasamoonshotaibytedanceexportpolicy

The chips banned from China never actually leave the data center. Chinese AI companies are reportedly renting access to them instead, from thousands of miles away.

White House official Michael Kratsios accused Moonshot AI of using Nvidia's restricted GB300 chips through a facility in Thailand, just days after the company released its Kimi K3 model in July.

A White House official gave CNBC a general statement rather than addressing the specific accusation, saying the administration has "implemented the most rigorous export control regime in modern history." The Commerce Department's Bureau of Industry and Security didn't respond to a request for comment.

How the Workaround Actually Works

The mechanism is straightforward once you see it. US export rules restrict shipping the physical chips to China.

They don't restrict a Chinese company from remotely accessing those same chips sitting in a data center somewhere else.

"It controls physical AI chips. It does not cover remote access to those chips," said Cassia King, senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy.

As long as a company like Moonshot isn't actually buying and owning the hardware directly, King said, the arrangement is legal.

ByteDance reportedly worked with Singapore-based cloud provider Aolani to access Nvidia compute in Malaysia, an arrangement the Wall Street Journal first reported in March. Alibaba and Tencent have used similar setups elsewhere in the region.

Aolani told CNBC its customers have no ownership or physical access to the underlying chips, and that its services are "fully compliant with all applicable regulations."

A Boom Built Partly on a Loophole

Southeast Asia's data center buildout is accelerating fast enough that the loophole looks less like an edge case and more like a business model.

Real estate firm JLL projects global data center capacity could roughly double to 200 gigawatts by 2030. Research firm DC Byte counts 31 planned 100-megawatt-plus facilities across Malaysia, Indonesia and Thailand today, up from just two.

That's real infrastructure, not a workaround dressed up as one. It's also compute Chinese AI labs can tap without ever importing a restricted chip.

Michelle Nie, a visiting fellow at the Center for a New American Security, doesn't mince words about the stakes.

"The point of chip export controls is to deny China the ability to train frontier AI using advanced U.S. chips," Nie said.

She called the remote-access gap a direct threat to national security.

The Fix Congress Hasn't Finished

A bill called the Remote Access Security Act would extend export controls to cover remote cloud access, not just physical hardware. It passed the House in January and has been stuck in the Senate since.

Even if it passes, Nie said, RASA alone wouldn't close the gap. It would give regulators authority to act, but a separate rule would still need to be written defining what compute counts, who's barred from accessing it, and how cloud providers verify customers.

King said the Bureau of Industry and Security could move fast once that authority exists, potentially within days with White House backing. Writing a rule that's both enforceable and doesn't paralyze legitimate cloud business is the harder part.

What This Means for Miami

The cheap, high-performing Chinese AI models MAIN has covered gaining traction with cost-conscious US businesses, including Moonshot's Kimi K3 and models from DeepSeek and Alibaba, are partly trained on compute accessed through exactly this loophole.

That's a compliance wrinkle worth knowing about, not just a geopolitical footnote. Miami's substantial customs brokerage and export compliance industry, already central to the region's trade with Latin America and Asia, is a natural fit to help local businesses understand where their AI vendors' training compute actually comes from, especially if RASA or a BIS rule eventually extends liability further down the supply chain than it reaches today.

← Back to World AI