U.S. Tightens Chip Controls on China, Seeks to Close Remote Access Loophole
Nashnova编辑部
Chinese firms are remotely tapping Nvidia GB300 chips through Southeast Asian data centers, skirting current export controls; Congress is pushing the Remote Access Security Act to close the gap, but the bill still faces legislative and implementation hurdles.
The chips are banned — so how are they still being used?
The US bars export of Nvidia's most advanced AI chips — including the GB300 — to China, but controls cover only the physical transfer of hardware, not remote cloud access.
This means → as long as a Chinese company does not buy or hold the physical chips, accessing their compute remotely from an overseas data center is entirely legal.
In plain terms = the rules stopped "shipping chips into China" but not "logging in from Thailand and running them."
Who is doing this, and how?
White House official Michael Kratsios publicly accused Chinese AI startup Moonshot AI in July of using Nvidia GB300 chips through a facility in Thailand; its Kimi K3 model drew scrutiny in that context.
ByteDance, Alibaba, and Tencent are also reported to be tapping Nvidia compute remotely through cloud providers in Thailand, Malaysia, and Japan.
This reflects a fully formed "detour chain": chips stay in Southeast Asian facilities, compute flows back to China over the network.
Can the Remote Access Security Act close the loophole?
Congress is considering RASA — the Remote Access Security Act — which would extend export controls to cover remote cloud access to restricted hardware and software.
The bill passed the House in January but has not yet received a Senate vote.
In plain terms = RASA gives the government the *authority* to regulate remote access, but the actual rules — what is covered, how compliance works — still need to be written separately by the Commerce Department.
Even if the bill passes, what stands in the way of enforcement?
Researcher Michelle Nie notes that RASA itself only grants authority — it does not execute; the Bureau of Industry and Security (BIS) must draft specific rules afterward.
Researcher Cassia King says BIS could move within days with White House backing, but the challenge is crafting rules that close the loophole without catching legitimate business in the crossfire.
This means → between passage and actual enforcement lies a rule-writing period, and the window stays open until that process is complete.
Will the industry cooperate? What about the Southeast Asian data-center boom?
The bill would require cloud providers to bear KYC (know-your-customer) and identity-verification compliance costs — a source of potential industry pushback.
Southeast Asian data-center capacity is expanding fast: JLL estimates global data-center capacity could double to 200 GW by 2030; Malaysia, Indonesia, and Thailand already have 31 planned 100 MW-plus projects, up from just 2 currently operational.
This reflects a core tension: regulators want to tighten the gate, but Southeast Asian compute infrastructure is growing far faster than oversight can keep up.
Content is for reference only, not financial advice.