• STICKY POST

Find Our Latest Video Reviews on YouTube!

If you want to stay on top of all of our video reviews of the latest tech, be sure to check out and subscribe to the Gear Live YouTube channel, hosted by Andru Edwards! It’s free!

Monday August 31, 2026 12:33 am

The US Is Reportedly Drafting a Rule to Stop China Renting the AI Chips It Can’t Buy


Nvidia GB300 NVL72 AI server hardware on display at a trade show booth.

American export controls on AI chips have always had a hole in them shaped like the cloud. You cannot ship an Nvidia Blackwell server to Beijing. You can, apparently, sit in Beijing and rent time on one that is racked in Bangkok. A new report says the Trump administration is finally writing a rule about that.

The Information reported this week that the Commerce Department is working on export controls aimed at Chinese companies' remote access to advanced AI compute in countries that do not have matching restrictions, with Thailand and Singapore named as the obvious examples. Per that reporting, Commerce could circulate the draft to industry trade groups for feedback as early as September. Every word of that is in the conditional. What exists is a draft described by sources. No rule has been proposed, published, or enforced, and the administration has not announced one.


Why the loophole exists

Compute is a service now. That is the entire pitch of the cloud, and it is why the chip controls leak. Export law was built around the idea that a controlled item is a physical object that crosses a border, and you stop it by stopping the shipment. But nobody needs to own a GPU to use one. They need an account, a credit card, and an API endpoint. The same property that makes renting compute useful (you never have to touch the hardware or be anywhere near it) is the property that makes a shipping ban easy to route around.

Chinese firms have been renting export-controlled Nvidia hardware through offshore cloud providers for years. The workaround is well enough known that Congress started legislating against it before the administration got around to drafting anything.

What "remote access" would have to cover

The reported rule would restrict access to advanced AI compute sitting in third countries that lack equivalent controls. Simple enough as a sentence. As a regulation it gets ugly fast, because somebody has to decide who counts as a Chinese entity, whether an offshore subsidiary counts, what happens when the customer of record is a Singaporean intermediary, and how a data center operator in Thailand is supposed to know any of that. In practice it means know-your-customer rules for GPU rentals.

There is also a straightforward legal problem. The Bureau of Industry and Security regulates the movement of things, and a remote login is not a shipment. Tom's Hardware's write-up of the report quoted an attorney making exactly that point, calling it widely acknowledged that Commerce has traditionally regulated goods in transit rather than access. Congress got there first. The House passed the Remote Access Security Act 369 to 22 on January 13, 2026, a bill from Rep. Mike Lawler that would give BIS explicit authority to control remote access to export-controlled items. Rep. John Moolenaar, who chairs the House Select Committee on China, said it "brings our laws into the digital age and makes it clear that cloud compute is subject to U.S. export control law, just like physical chips." The Senate companion was still waiting on a vote as of this summer.

The "cut-down AI diffusion rule" part

The framing in the report is that this would be a narrower version of the AI diffusion rule, and that framing carries some history. The Biden administration published the original diffusion rule in January 2025, sorting the world into tiers with compute caps attached. BIS rescinded it in May 2025 after heavy industry pushback. A replacement framework circulated as a draft in February 2026, with tiered licensing and a requirement that operators of the largest clusters make matching investments in US infrastructure, and it was pulled from the regulatory agenda in March 2026 before it went anywhere. One got published and then pulled, the other never made it out of draft. A rule that targets one specific hole is a much smaller ask than a rule that reorganizes global chip trade, which may be the point.

Why now

In July, White House OSTP director Michael Kratsios publicly accused Moonshot AI of distilling a US model and training its Kimi K3 model on Nvidia-equipped servers reached through Thailand. That is an allegation from an administration official, not a finding, and it has not been adjudicated anywhere. But it put a company and a country on a problem that had mostly been argued in the abstract.

The argument against

Critics of remote access controls have a real argument. You cannot delete demand for compute, you can only relocate it. If US cloud providers have to verify every customer's nationality and turn away anything ambiguous, the customers who get turned away do not stop training models. They go to Huawei Cloud or Alibaba Cloud. Writing in The Diplomat in July, Charles Mok argued that broad restrictions risk pushing legitimate customers in third countries off American infrastructure and into a Chinese stack that is courting them.

Enforcement is the other soft spot. The Government Accountability Office has found BIS stretched thin policing physical hardware exports alone, and monitoring who is logging into which foreign data center is a considerably larger job. The Carnegie Endowment's survey of the debate raises a point that cuts against the hawks. Chinese firms renting American-linked compute also gives US agencies a view of what those firms are building. Push them onto domestic Chinese infrastructure and that window closes.

And there is the diplomatic cost of telling data centers on other countries' soil which customers they may serve. Southeast Asian governments that have spent the last few years courting AI infrastructure investment are unlikely to enjoy it.

What to watch

If you operate a GPU cloud or a data center anywhere in Southeast Asia, September is the month to pay attention, because the first real signal will be whether Commerce sends anything to trade groups at all. The last attempt at a broader rule never got past that stage.

For everyone else, the thing to track is scope. A rule aimed narrowly at entities already on the Entity List is a very different animal from a rule that makes every cloud provider a customs officer. Right now nobody outside Commerce knows which one is being written, and the people who do know are not saying.

Latest Andru Edwards Videos

Advertisement

Advertisement