Chinese AI developers lease Nvidia capacity in foreign data centers through non Chinese proxy entities, a workaround the House and the Commerce Department's Bureau of Industry and Security (BIS) are now trying to cut off.
Chinese AI firms are renting advanced AI training chips from Nvidia abroad through non-Chinese proxy entities in Southeast Asia, Japan, and the Middle East, and Washington is now weighing whether to close that cloud-routing loophole with new compute curbs.
The mechanism, described by the South China Morning Post, works like this. A Chinese AI developer cannot legally buy the world's most powerful AI training chips. So the company sets up a proxy entity, what the Post calls a "non-Chinese contracting vehicle," in a foreign jurisdiction. That entity signs the lease on server space in a data center overseas. The Nvidia hardware sits there, outside US reach, and the Chinese developer pays to train on it. Contracts are signed by non-Chinese parties, which is what keeps the arrangement in a legal gray zone rather than an outright violation. The result is that the same Nvidia silicon a Chinese lab cannot buy at home, it can rent a thousand miles away.
The House of Representatives passed the bipartisan Remote Access Security Act in January 2026, framed by the House Select Committee on the CCP as a way to limit adversaries' remote access to critical technology, including AI compute routed through US clouds. The Bureau of Industry and Security then moved in August 2026 to target legal cloud compute as a chip-control workaround. Caixin Global and CNBC both framed the moves as the US trying to close a crucial loophole after banning Nvidia's best chips from China directly.
Chip curbs limited what hardware Chinese labs could buy. Cloud curbs would limit what hardware Chinese labs could rent, and from which jurisdictions. The two restrictions together would push Chinese frontier-model training onto smaller, less efficient chips, or into third-country data centers where the US has bilateral leverage. Either outcome reshapes the cost curve for Chinese AI development and the geography of where new models are built.
The mechanism is also fragile, in sourcing and in legal status. The South China Morning Post's proxy-entity detail depends partly on an anonymous Shenzhen broker, a constraint the rest of the reporting does not reinforce. House committee, BIS, Caixin, and CNBC coverage all confirm the regulatory trajectory. The specific proxy-entity structure should be read as one reported channel, not a universal one. Cloud curbs, for their part, are "weighing," not announced. The next escalation is in active policy review, not in published rule text.
A second wave of adaptation is already visible. Vision Times reported Chinese firms finding new routes around US chip controls as Washington moved to close the cloud loophole, which is the expected pattern. Every closure on one channel pushes the workaround to the next one. The likely next channels are domestic Chinese AI chip capacity, sovereign data centers in third countries with looser US alignment, and over-the-counter access through smaller cloud providers outside the major hyperscalers.
The proxy-rental workaround turned a chip ban into a compute access question. Washington is now trying to turn that into a jurisdiction question. Where Chinese frontier models get built, and on whose hardware, is the regulatory question US rulemakers are now writing for.