US export controls were built to stop chips from reaching China. Remote access is testing the rule.
The US has spent years trying to keep Nvidia's most advanced AI chips out of China. The Bureau of Industry and Security, the Commerce Department arm that administers export controls, closed one major gap on 31 May 2026: any advanced computing chip shipped to a company headquartered in China, Macau, or another designated jurisdiction now needs a license, even when the chip lands at a subsidiary sitting outside Chinese territory. The rule targets the ownership dodge, where a Chinese-owned subsidiary in a third country could legally take delivery of Nvidia's top-end silicon.
The bigger gap is still open. A Chinese firm can rent time on Nvidia hardware in a Malaysian or Singaporean data center, never take physical possession of a chip, and still train a frontier model. The 31 May guidance (BIS press release, 31 May 2026 PDF guidance, Reuters) governs shipments. It doesn't yet govern access.
Reuters reported on 27 November 2025 that Alibaba and ByteDance are training their newest large language models, the Qwen and Doubao families, at data centers in Singapore and Malaysia to keep working with Nvidia hardware under US restrictions (Reuters). The arrangement lets the labs pay for computing power rather than buy chips, so the chips technically never leave Singapore or Malaysia. That distinction is the heart of the new control problem: physical export rules were written for a world where the hardware has to physically arrive.
The H200 channel is the legal route on the other side of the same fence. Under Federal Register rule 2026-00789, issued on 15 January 2026, Nvidia's top-end AI accelerators, including the H200, and AMD's MI325X, exports to China and Macau moved from a presumption of denial to case-by-case review, subject to security conditions including a total processing performance cap under 21,000 and DRAM bandwidth under 6,500 GB/s (Federal Register). That licensed channel is a controlled, conditional flow of hardware. The Southeast Asia data-center route is a workaround outside the export-control perimeter, and the two shouldn't be conflated.
Nvidia is already tightening the screws it can reach. Reuters reported on 14 July 2026 that the company halved its approved Asian buyer list and increased checks on buyers in Malaysia and Singapore to stop chips reaching China through third countries (Reuters). That is a commercial enforcement layer on top of a regulatory layer; it doesn't, by itself, touch a Chinese firm that rents time on a chip it never orders, receives, or resells.
The next move, if Memeburn's analysis is right, is the cloud-rental path itself (Memeburn). No public BIS rule, proposed rule, or pending bill specifically targets remote compute access yet, and "next on the hit list" is the publication's editorial framing rather than a confirmed Washington action. But the policy logic is visible: if the underlying control premise is "stop the hardware from reaching Chinese hands," a rental model that never delivers hardware to those hands is the obvious next gap to close. ByteDance is reported to be negotiating to buy more than 50,000 chips from Chinese vendor Iluvatar CoreX while developing its own accelerators, a parallel track that suggests the labs are hedging against exactly this kind of access squeeze.
The physical shipment has been the export-control surface for half a decade. The next surface is a rental agreement.