The proposed rule would treat a Chinese company’s remote use of controlled Nvidia AI hardware in overseas data centers as an export control event. The alleged workaround is straightforward: Chinese companies rent computing capacity from data centers in places such as Thailand, Singapore and Malaysia, while the GPUs...
Research answer

Create a landscape editorial hero image for this Studio Global article: What is the Trump administration’s proposed export-control rule to prevent Chinese companies from remotely accessing advanced Nvidia AI chip. Article summary: The proposed rule would treat a Chinese company’s remote use of controlled U.S. AI hardware—such as Nvidia GPUs installed in a foreign cloud or data center—as an export-controlled event, rather than regulating only the c. Topic tags: general, news, general web, government, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermar
The Trump administration is considering a rule that would regulate remote access to advanced AI compute as well as the physical export of the hardware. The target is a gap in the current system: a Chinese company can potentially rent computing power from Nvidia GPUs installed in a third-country data center without importing or owning the chips in China. Reporting says the proposal could focus on remote servers in countries such as Thailand and Singapore, although it has not yet become an enforced regulation. 7
16
Existing U.S. export controls are principally structured around the export, reexport or transfer of controlled items, including advanced-computing chips and equipment. That makes it possible to screen a shipment’s destination, buyer and end use. The rules are less clear when the physical server never moves and a customer simply submits model-training or inference workloads over the internet. 8
9
The arrangement reportedly works like this:
That distinction—ownership and location of the hardware versus access to its computing capacity—is why officials and lawmakers describe remote cloud use as a potential loophole. Reports have named Alibaba, ByteDance, Tencent and Moonshot among Chinese companies using or seeking advanced Nvidia compute outside China, including in Southeast Asia. 5
8
On May 31, 2026, the Commerce Department’s Bureau of Industry and Security said a license is required for exports of covered advanced-computing items to entities headquartered in Country Group D:5, which includes China, or to entities whose ultimate parent is headquartered there—even when the immediate entity is located elsewhere. 18
21
That guidance makes it harder for a Chinese company to obtain controlled chips through an overseas subsidiary, affiliate or related purchasing vehicle. It follows the corporate relationship rather than relying only on the flag of the country where the buyer is incorporated. 18
31
But the guidance primarily addresses the shipment or acquisition of equipment. Reuters reported that it does not generally require third-country data centers to stop using, servicing or renting out chips that are already installed there. 1 In practical terms, it closes part of the ownership and procurement route without clearly resolving whether remote consumption of compute is itself an export under existing law.
The issue gained additional attention after Michael Kratsios, director of the White House Office of Science and Technology Policy, alleged that Moonshot AI had acquired GB300-equipped servers and accessed GB300 chips in Thailand, likely to train its AI models. 2
10
The allegation was discussed in connection with Moonshot’s Kimi model family, including Kimi K3. It should be treated as an allegation, not as a confirmed export-control violation: the provided reporting does not establish a final Commerce Department enforcement finding or court judgment.
Other reporting has described Chinese technology companies arranging access through data centers and cloud providers in Malaysia, Thailand, Japan and Singapore. Those accounts differ on the companies, facilities and hardware involved, so the broader pattern is best described as reported or alleged access, rather than a fully established set of violations. 6
8
41
The proposed approach would move the focus from where the GPU sits to who is using its controlled capability. Depending on its final language, Commerce could require cloud operators, data centers or intermediaries to screen customers before allowing access to specified chips or compute clusters.
A rule could potentially address:
The exact scope matters. A workable regime would need to define which chips and systems are covered, how much computing capacity triggers controls, whether short-term rentals are treated differently from dedicated clusters, and how providers should identify the actual end user behind a reseller or shared account.
The House-passed Remote Access Security Act, or RASA, would amend the Export Control Reform Act to expressly address certain forms of remote access. Its definition covers access by a foreign person through a network connection—including the internet or a cloud-computing service—from a location different from where the controlled item is physically located, when the use could pose a serious national-security or foreign-policy risk. 46
48
49
The House passed H.R. 2683 on January 12, 2026, by a 369–22 vote. The bill would provide Commerce with a substantially clearer statutory basis for regulating cloud-based access, although a separate rulemaking would still be needed to determine what conduct and technology are controlled. 50
55
That distinction is important: RASA is not itself a complete operating rule for every cloud provider. It is an authority-expanding measure intended to let the department build such a regime.
Without enacted legislation such as RASA, Commerce would have to argue that existing terms such as “export,” “reexport” or “transfer” already cover remote consumption of computing power when the chip itself never moves. Legal analyses describe the core ECRA authority as covering exports, reexports and in-country transfers of items, which helps explain why Congress proposed an express remote-access definition. 56
61
A guidance document can clarify how an existing requirement applies, as the May 31 notice did. It is less certain whether guidance or a new regulation alone can create an entirely new category of regulated conduct. A broad rule could therefore face a challenge that Commerce exceeded its delegated authority or acted without sufficiently clear congressional direction.
Shipment screening usually starts with a consignee and a physical destination. Cloud access is more fluid. Providers may need to assess subsidiaries, ultimate parents, resellers, contractors, virtual private networks, shared clusters and accounts that obscure the person actually running the workload.
That would push cloud companies toward know-your-customer-style controls and more extensive monitoring. Analysts have identified increased customer verification as a likely implementation requirement under a remote-access regime. 3
11
The server, data-center operator, customer contract and end user may all be located outside the United States. Commerce can use export restrictions, licensing leverage, U.S.-origin technology rules and penalties against parties with a relevant U.S. connection. It cannot automatically compel every Thai, Singaporean or Malaysian facility to enforce U.S. policy without local cooperation or contractual leverage over suppliers.
A rule that is too narrow could be easy to evade through intermediaries or non-U.S. hardware. A rule that is too broad could burden ordinary multinational cloud services, foreign data-center operators and legitimate research users. Providers would also need clear tests for chip performance, cluster size, duration of access and the purpose of a workload.
The proposed rule is best understood as an attempt to regulate access to AI compute, not simply the movement of AI chips. The May 31 BIS guidance makes physical shipments to China-linked entities abroad more difficult, but the remote-rental question remains distinct. RASA would give Commerce stronger statutory footing, while enforcement would still depend on precise regulations, provider due diligence and cooperation from countries hosting the infrastructure.
For now, the central caveat is status: the administration’s remote-access measure is under consideration, and allegations involving companies such as Moonshot AI do not by themselves establish violations. The policy debate is about whether U.S. export controls should follow the physical chip, the company that owns it, the customer that rents it—or the computing capability itself.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The proposed rule would treat a Chinese company’s remote use of controlled Nvidia AI hardware in overseas data centers as an export control event.
The proposed rule would treat a Chinese company’s remote use of controlled Nvidia AI hardware in overseas data centers as an export control event. The alleged workaround is straightforward: Chinese companies rent computing capacity from data centers in places such as Thailand, Singapore and Malaysia, while the GPUs remain outside China.
The House passed Remote Access Security Act would give Commerce clearer authority to regulate this kind of cloud access, but enforcement would still require customer verification, workable technical thresholds and coo...