Tech & AI

How Chinese AI Labs Are Quietly Training on Banned Nvidia Chips — and Why Current Rules Allow It

The headline version of US chip policy is simple: America’s most advanced Nvidia AI chips are banned from export to China. The reality on the ground is considerably messier, and the gap between the two is now a genuine national security debate in Washington.

The loophole, explained plainly

US export controls restrict the physical transfer and ownership of advanced AI chips. They do not, as currently written, restrict remote access to the computing power those chips provide once they’re installed somewhere else. That distinction matters enormously in practice: a Chinese AI company can’t legally buy and ship home a container of restricted Nvidia chips, but it can reportedly rent time on a cloud server in Thailand, Malaysia, or Indonesia that happens to be running on exactly those chips.

One specific case that surfaced this year involved the Chinese AI lab Moonshot reportedly accessing advanced Nvidia compute through a data center in Thailand. According to a compute-policy researcher who spoke with CNBC, this arrangement is legal under current rules as long as the Chinese company isn’t directly buying or physically owning the hardware — the restriction covers the chips themselves, not who’s allowed to rent time on them remotely.

Why this loophole exists at scale right now

This isn’t a one-off workaround — it’s riding a genuine regional infrastructure boom. Real estate firm JLL estimates global data center capacity could roughly double to 200 gigawatts by 2030, and there are reportedly 31 data centers larger than 100 megawatts planned across Malaysia, Indonesia, and Thailand alone, compared with just two such facilities today. That buildout is happening partly because Southeast Asia has become a convenient, well-capitalized middle ground for exactly this kind of cross-border compute access.

Lawmakers are aware of the gap. A proposed bill, the Remote Access Security Act (RASA), would expand export controls to cover remote cloud-based access to restricted chips, not just their physical transfer. Whether it passes — and how it would be enforced given how hard remote compute access is to monitor — remains an open question.

A complicated, shifting backdrop

This loophole story sits on top of an already tangled policy history. In December 2025, the US allowed Nvidia to resume selling its capable H200 chip to China, provided the US government received a cut of the revenue. The Commerce Department codified that policy in January 2026 with a volume cap — one large enough, according to the Council on Foreign Relations, to let China build some of the largest AI data centers in the world, while still officially restricting the most advanced hardware. CFR analysts called the resulting framework “strategically incoherent,” since it acknowledges the national security risk of the exports while creating a formal pathway to allow them anyway.

Layered on top of that: Nvidia’s own market share inside China has reportedly collapsed from roughly 95% in 2023 toward near-zero on new shipments by mid-2026, as Chinese buyers increasingly turn to domestic alternatives like Huawei — meaning the remote-access loophole and the direct-sales question are now separate, sometimes contradictory storylines happening at the same time.

The bottom line

Chip export controls were built around a simple mental model: control the hardware, control who can train the most powerful AI models. That model assumed the hardware and the training would happen in the same place. Once cloud computing lets you rent power from a chip sitting in another country entirely, the enforcement question shifts from “what can we ship” to “what can we actually monitor” — and right now, the honest answer is: not much.

Why closing this loophole is harder than it sounds

Even if RASA or something like it passes, enforcement runs into a practical wall: distinguishing a Chinese company renting cloud compute for a legitimate reason from one deliberately routing around export controls requires visibility into who’s actually using a data center’s capacity, not just who owns it. Southeast Asian data center operators have every commercial incentive to fill capacity regardless of the customer’s nationality, and unlike a physical chip shipment, there’s no customs checkpoint for a cloud API call. Some proposals under discussion would require cloud providers to verify and report the end users of compute above certain thresholds — essentially a “know your customer” rule borrowed from financial regulation — but that raises its own questions about how reliably self-reported usage data can be verified from outside the facility.

There’s also a geopolitical wrinkle: several of the countries hosting this new data center capacity, including Malaysia and Indonesia, are treating the AI infrastructure boom as a genuine economic development opportunity and have limited incentive to police who’s renting time on servers within their borders. Any US enforcement approach that leans too hard on these countries risks straining relationships Washington needs for other strategic reasons in the region — which is likely part of why, so far, the policy response has moved more slowly than the workaround itself has spread.

Eminetra Editorial Team

The Eminetra Editorial Team covers business, technology, and policy stories, focusing on clear explainers over breaking-news churn. Have a tip or correction? Contact us at eminetra.com@gmail.com.