US seeks to close AI chip loophole as Chinese firms access Nvidia compute via Southeast Asia
US moves to close a loophole letting Chinese firms remotely access Nvidia's most powerful chips via Southeast Asian data centers, CNBC reports.
The effort comes less than a week after Chinese AI startup Moonshot AI released its Kimi K3 model in July. White House official Michael Kratsios accused the company of using Nvidia's GB300 chips via a facility in Thailand. Moonshot is one of several Chinese firms, including DeepSeek and Alibaba, that have recently released models with strong performance on benchmarks.
Nvidia's most powerful chips are subject to export restrictions to China, but some less capable semiconductors are allowed. However, several Chinese firms have reportedly accessed the compute power of restricted chips remotely through cloud providers in Southeast Asian nations such as Thailand, Malaysia and Japan. ByteDance, Alibaba and Tencent were named in reports. Alibaba declined to comment; ByteDance and Tencent did not respond to CNBC's requests.
According to a source familiar with the matter, ByteDance worked with Singapore-based cloud provider Aolani to access compute in Malaysia. Aolani told CNBC that the companies it services do not have ownership or physical access to the chips powering its solutions, and that any permitted access is fully compliant with applicable regulations.
A White House official told CNBC: "The Trump administration has implemented the most rigorous export control regime in modern history, and remains committed to safeguarding America's national and economic security."
Experts say the loophole threatens U.S. national security. "The point of chip export controls is to deny China the ability to train frontier AI using advanced U.S. chips," said Michelle Nie, a visiting fellow at the Center for a New American Security. Cassia King, senior researcher at the Institute for AI Policy and Strategy, noted that the U.S. export control regime "controls physical AI chips. It does not cover remote access to those chips."
To address this, the Remote Access Security Act (RASA) has been proposed. The bill, which passed the House in January, would expand export controls to cover remote cloud-based access to critical hardware and software. It has yet to pass the Senate. Nie said the bill could face industry pushback because cloud providers would bear the compliance burden of customer verification requirements.
Even if RASA passes, it would only give the government authority to regulate remote access; a rule would still need to be created. However, King said the Bureau of Industry and Security could push through a rule quickly with White House support, possibly in a matter of days. The challenge will be making a rule that is effective and enforceable, she added.
The AI infrastructure boom in Southeast Asia is adding urgency. According to data from DC Byte, there are 31 planned 100MW+ data centers across Malaysia, Indonesia and Thailand, compared to just two today. JLL estimates global data center capacity could roughly double to 200GW by 2030.