Nvidia’s dominance in high-end AI processors has turned U.S. export controls into one of Washington’s most important levers for protecting its technological edge over China.
Yet even as the United States restricts shipments of Nvidia’s top-tier semiconductors, including the GB300, reports suggest some Chinese companies have still tapped the chips’ computing power through data centers based in Southeast Asia.
In July, less than a week after Moonshot AI unveiled a new model, White House official Michael Kratsios alleged that the company had used Nvidia GB300 chips through a facility located in Thailand.
Moonshot’s Kimi K3 is part of a broader surge in Chinese AI systems that have shown significant performance gains in recent months, raising the stakes in the growing artificial intelligence rivalry between the U.S. and China. DeepSeek and Alibaba have also introduced new models that performed strongly on industry benchmarks.
Analysts say remote access to advanced computing resources through foreign cloud providers has become an important driver behind the rapid improvement of Chinese AI models. U.S. lawmakers are weighing measures aimed at closing that gap, though significant challenges remain before any new rules could take effect.
How Chinese firms access Nvidia computing power overseas
Nvidia’s most powerful AI chips are currently barred from export to China, although Washington still permits some lower-performance semiconductors to be sold into the market.
Cassia King, a senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy, told CNBC that Moonshot’s reported use of computing power through a Thai site would be legal “so long as Moonshot isn’t actually buying and owning the physical hardware directly.”
King said the current U.S. export control system “controls physical AI chips. It does not cover remote access to those chips.”
When asked about Chinese firms accessing Nvidia compute overseas to train AI models, a White House official told CNBC: “The Trump administration has implemented the most rigorous export control regime in modern history, and remains committed to safeguarding America’s national and economic security.”
The U.S. Department of Commerce and Bureau of Industry and Security (BIS) did not respond to a request for comment.
Chinese hyperscalers including ByteDance, Alibaba and Tencent have reportedly accessed compute power from Nvidia chips remotely via other Asian nations, including Thailand, Malaysia and Japan. ByteDance and Tencent did not respond to a request for comment. Alibaba declined to comment.
ByteDance was working with Singapore-headquartered Aolani, a cloud provider with Nvidia chips, to access compute in Malaysia, according to a source familiar with the matter, who asked to remain anonymous when discussing private information. The Wall Street Journal first reported the arrangement in March.
Aolani told CNBC it worked “with a global and diversified customer base spanning customers from North America and Asia.”
“The companies we service do not have ownership, potential future claim or physical access to the chips that power our solutions,” the spokesperson added. “Any permitted access to our services, infrastructure or technology is fully compliant with all applicable regulations.”
AI infrastructure buildouts in Southeast Asia are booming as companies look to tap the growing market for advanced compute.
Real estate company JLL estimates that global data center capacity could roughly double to 200GW by 2030.
There are 31 planned 100MW+ data centers across Malaysia, Indonesia and Thailand, compared to just two today, according to data compiled by DC Byte.
What the Remote Access Security Act would change
Michelle Nie, a visiting fellow in technology and national security at think tank Center for a New American Security, told CNBC that loophole was “threatening U.S. national security.”
“The point of chip export controls is to deny China the ability to train frontier AI using advanced U.S. chips,” she added.
A proposed piece of legislation, the Remote Access Security Act (RASA), seeks to expand U.S. export controls to include the remote cloud-based access of critical hardware and software. It passed the House of Representatives in January but has yet to pass the Senate.
It faces potential industry pushback, Nie said, adding: “Cloud providers would bear the compliance burden of any KYC and customer verification requirements mandated by the bill.”
The passing of RASA alone wouldn’t solve the problem, Nie added, saying it would give the U.S. government “the authority to regulate remote access,” but it “would still need to create a rule to export-control remote access to advanced chips.”
The Bureau of Industry and Security (BIS) could push through a rule quickly, possibly in a “matter of days” with White House support, said King.
“The challenge will be in making a rule that’s effective and enforceable,” she added. “Policymakers will need to decide what compute is covered, who should be prohibited from remotely accessing the compute, and how to implement a robust know-your-customer scheme.”
