Policy & Geopolitics
Export Controls Miss the Cloud. That Ends Soon
Chinese labs reach restricted Nvidia chips by renting them abroad. A bill covering remote access has sat in the Senate for 219 days.
The U.S. export-control regime covers physical AI chips and not remote access to them, and Chinese labs have been using the gap. CNBC reports that after Moonshot AI released a new model in July, White House official Michael Kratsios accused the company of using Nvidia GB300 chips through a facility in Thailand. Cassia King of the Institute for AI Policy and Strategy told CNBC the arrangement was legal “so long as Moonshot isn’t actually buying and owning the physical hardware directly,” because the regime “controls physical AI chips. It does not cover remote access to those chips.”
The legislative fix exists and is stalled. The Remote Access Security Act, H.R. 2683, was received in the Senate and referred to the Banking Committee on January 13, 2026 after passing the House; its stated purpose is “to provide for control of remote access of items under the Export Control Reform Act of 2018.” That referral is 219 days old as of today, and the official GovInfo record of the referred-in-Senate version shows no action since. A one-sentence statutory change has spent seven months in committee while the capacity it would govern was under construction.
The capacity is being built where the rules aren’t
The infrastructure numbers explain the urgency better than the rhetoric does. CNBC cites DC Byte data showing 31 planned 100MW-plus data centers across Malaysia, Indonesia and Thailand against just two today — a 15.5× increase in large-facility count in a region that sits outside the physical-chip perimeter. JLL estimates global data center capacity could roughly double to 200GW by 2030. Chinese hyperscalers including ByteDance, Alibaba and Tencent have reportedly reached Nvidia compute remotely through Thailand, Malaysia and Japan, and a Singapore-headquartered provider told CNBC its customers “do not have ownership, potential future claim or physical access to the chips.”
Capital is arriving faster than rules. Nvidia this month signed memorandums of understanding with six asset managers to mobilize more than $500 billion of third-party capital for AI compute infrastructure, financing that is explicitly global and indifferent to which jurisdiction a rack lands in. Every dollar of that program that funds capacity in a permissive corridor widens the surface any future rule has to cover. The regulator writes the perimeter after the concrete has cured.
That sentence is the whole loophole, stated as a compliance defense. It is also, read carefully, an accurate description of how every cloud works. Which is why the fix is harder than passing the bill. Michelle Nie of the Center for a New American Security told CNBC that RASA alone “would still need to create a rule to export-control remote access to advanced chips,” and King said the Bureau of Industry and Security could move in a “matter of days” with White House support but that “the challenge will be in making a rule that’s effective and enforceable” — deciding what compute is covered, who is barred, and how know-your-customer works.
What an operator does with 219 days of warning
If you rent GPU capacity in Southeast Asia, or resell it, or serve customers who might, the planning assumption should be that a KYC regime arrives with little notice and lands on the cloud provider. Nie’s point is that “cloud providers would bear the compliance burden of any KYC and customer verification requirements mandated by the bill.” Providers who cannot attest to end-customer identity and nationality on short notice will face the choice between suspending accounts and accepting legal exposure. Both outcomes reach the tenant.
There is a second-order effect worth naming. If remote access becomes controlled, the compliance cost lands on providers, and providers price it. Attestation, identity verification, and audit are not free, and in a market where GPU-hours are becoming a tradable reference price with October futures, a KYC surcharge shows up as a regional spread that anyone reading the curve can see. Compliance geography becomes a line item, which is a strange but useful outcome: the cost of the rule becomes legible before the rule exists.
Three concrete moves. Inventory where your inference and training capacity physically sits, by facility and operator, not by cloud-region label — the region string is a billing abstraction, not a jurisdiction. Second, ask each provider in writing whether it can produce end-customer attestation today, and treat a vague answer as a scheduling risk rather than a legal one. Third, price a migration path for any workload whose capacity sits in the affected corridor, because the cost of moving is knowable and the cost of a suspended account in the middle of a training run is not.
The counterargument deserves weight: this may never bind. RASA has to clear the Senate, then BIS has to write a rule that distinguishes a Chinese frontier lab from a Malaysian startup renting the same rack, and the industry pushback Nie anticipates is real. Enforcement against remote access requires knowing who is on the other end of an API key, which is precisely the thing anonymous cloud provisioning is designed to obscure. The archive’s account of the smuggling ring that moved $2.5 billion of restricted hardware is the reminder that physical controls leak too.
The verdict: treat the loophole as closing, not closed, and buy optionality rather than certainty. The evidence that would change the call is a Senate floor vote or a BIS proposed rule with a defined compute threshold — either one converts a seven-month stall into a compliance deadline. Until then the same lesson governs here as in today’s lead on the routing layer becoming a priced asset: know exactly where your dependency physically lives, because someone else is about to put a price or a rule on it.
Sources
- CNBC — Chinese firms reaching restricted Nvidia compute through Southeast Asian data centers
- GovTrack — text and Senate referral history of H.R. 2683, the Remote Access Security Act
- GovInfo — official record of H.R. 2683 as referred in the Senate
- NVIDIA — the financing platforms underwriting global AI compute buildout