Chinese AI firms access restricted Nvidia chips via Southeast Asia
U.S. export controls target physical hardware, leaving a cloud access loophole that proposed legislation aims to close.

Chinese artificial intelligence companies are gaining access to Nvidia's most powerful chips despite U.S. export restrictions, using a legal workaround that has Washington scrambling to respond.
Several Chinese firms, including Moonshot AI, have reportedly accessed computing power from Nvidia's restricted GB300 chips through data centers located in Southeast Asian countries. In July, White House official Michael Kratsios publicly accused Moonshot of using GB300 chips via a facility in Thailand, less than a week after the company released its Kimi K3 model.
The export control gap
The arrangement exploits a fundamental limitation in current U.S. policy: export controls regulate the physical sale and ownership of advanced semiconductors, but they don't cover remote access to those chips through cloud computing services.
"So long as Moonshot isn't actually buying and owning the physical hardware directly," the practice remains legal under existing rules, according to Cassia King, senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy, as reported by CNBC.
Chinese technology giants ByteDance, Alibaba, and Tencent have all reportedly accessed Nvidia computing power remotely through facilities in Thailand, Malaysia, and Japan. ByteDance worked with Singapore-based cloud provider Aolani to access compute resources in Malaysia, according to a source familiar with the arrangement.
Aolani confirmed to CNBC that its customers "do not have ownership, potential future claim or physical access to the chips that power our solutions," and stated that all access is "fully compliant with all applicable regulations."
Southeast Asia's data center boom
The region is experiencing explosive growth in AI infrastructure. Malaysia, Indonesia, and Thailand currently have 31 data centers of 100 megawatts or larger either planned or under construction, compared to just two operational facilities of that scale today, according to data compiled by DC Byte. Real estate firm JLL projects global data center capacity could double to 200 gigawatts by 2030.
Proposed legislative fix
The Remote Access Security Act (RASA), which passed the House of Representatives in January but awaits Senate action, would extend U.S. export controls to include remote cloud-based access to critical hardware and software.
However, Michelle Nie, a visiting fellow at the Center for a New American Security, told CNBC that passing the legislation is only the first step. The Bureau of Industry and Security would still need to create implementing rules defining which computing resources are covered, who should be prohibited from accessing them, and how to enforce know-your-customer requirements.
King noted that BIS could potentially push through such rules quickly with White House backing, but cautioned that "the challenge will be in making a rule that's effective and enforceable."
Why it matters
The cloud access loophole undermines a cornerstone of U.S. strategy to maintain its lead in artificial intelligence development. Chinese AI models from companies including DeepSeek, Alibaba, and Moonshot have made significant performance gains in recent months, with industry observers citing access to advanced computing power through overseas providers as a key enabling factor. Without effective controls on remote access, physical chip export restrictions may prove insufficient to slow China's AI capabilities.
These details were first reported by CNBC.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
