US Drafts Rule to Close the Remote GPU Rental Loophole — but Lawyers Say BIS Lacks the Authority
Commerce is preparing a September rule to block Chinese AI firms from renting Nvidia GPU time through Thai and Singapore data centers, but export-control lawyers say BIS has no statutory authority over remote compute access.
The US Commerce Department is drafting a rule that would make it illegal to rent Nvidia GPU computing time to Chinese AI companies through data centers in Thailand and Singapore, according to a report by The Information. A draft could be shared with industry trade groups as early as September — a procedural step that signals a formal rulemaking commitment rather than exploratory review. But the lawyers who follow US export controls most closely say the department almost certainly lacks the statutory authority to enforce it, setting up a high-stakes collision between national security urgency and administrative law.
The rule targets the “remote access” loophole: when a Chinese AI lab sends training jobs over the internet to an Nvidia GPU cluster sitting in a Bangkok or Singapore data center, no chip crosses a border in any sense that current export regulations recognize. The cluster stays in its rack. Under US law as it has stood since 2009, that is not an export — and Chinese AI firms have used exactly that gap to train frontier models on US silicon Washington never intended them to touch.
The loophole that was never really closed
The legal gap at the center of this story was not created by oversight. It was created deliberately — by a 2009 Bureau of Industry and Security (BIS) cloud computing opinion, plus advisory opinions in 2011 and 2014, that gave the cloud-computing industry a foundational assurance: when a provider makes computing capacity available to a foreign customer and the hardware never moves, no export has occurred. The provider is not the exporter; the user never receives a “release” of a controlled item in the sense that 15 CFR § 734.2 requires.
That holding made the modern cloud industry viable. It also established, as a direct architectural consequence, that a Chinese AI lab sending training jobs to an H100 cluster in Thailand triggers no US export controls whatsoever.
And the gap grew wider. The Biden administration, in its final weeks, established the Foundry Due Diligence Rule — a know-your-customer requirement obligating cloud providers and data-center operators to verify who their end users actually are before provisioning advanced AI compute. The Trump administration inherited that rule, declined to enforce it, and publicly said it would not do so. In the 18 months that followed, Chinese AI labs used precisely the access that rule would have forced them to disclose.
Kimi K3: the catalyst
The immediate trigger for moving from review to rulemaking was Kimi K3, unveiled by Moonshot AI at the World Artificial Intelligence Conference in Shanghai on July 16, 2026. The 2.8-trillion-parameter open-weight mixture-of-experts model ranked near the top of global capability assessments and outperformed several leading American systems on coding and web-development tasks — setting off a market reaction that wiped an estimated $3.3 trillion in semiconductor market value during its release week.
On July 22, White House Office of Science and Technology Policy Director Michael Kratsios publicly accused Moonshot of training Kimi K3 on Nvidia GB300 Blackwell processors accessed through servers in Thailand — the most capable AI accelerators Nvidia manufactures and among the most tightly restricted for Chinese buyers. He further alleged that Moonshot built a “sophisticated internal platform” to extract capabilities from US models at scale through knowledge distillation. Anthropic separately reported unauthorized query surges to its Fable model that it attributed to the same effort. The allegations remain unverified; Moonshot has not publicly addressed them, and Nvidia says it complies with all export regulations.
What is independently confirmed is a related arrangement: Bloomberg’s July 31 investigation established that Moonshot trained Kimi K3 on roughly 20,000 Hopper-generation Nvidia chips supplied through Alibaba’s cloud infrastructure — a compute-rental arrangement existing export controls were simply not designed to reach. Alibaba disputed that the chips were H200s, the most capable Hopper parts, but did not deny the arrangement existed.
The pattern extends well beyond Moonshot. Shanghai-based INF Tech accessed approximately 2,300 Blackwell GPUs through a rental deal with an Indonesian telecom worth roughly $100 million. Tencent secured access to about 15,000 Blackwell processors through Japanese cloud provider Datasection in contracts worth approximately $1.2 billion. ByteDance, Alibaba, and Tencent have all reportedly accessed Nvidia compute through Southeast Asian and Japanese data centers under similar arrangements. Research from IAPS estimated that offshore compute-rental arrangements could be boosting China’s effective access to advanced US compute by at least 60 percent in 2026 relative to what chip export controls would otherwise permit.
Why Commerce may not be able to enforce its own rule
The legal problem is structural, and it is twofold.
First, BIS’s own advisory opinions from 2009, 2011, and 2014 told the entire cloud industry that remote compute provision is not an export event. Under administrative law, those opinions bind the agency itself. Reversing a 15-year-old position through enforcement against a specific company — rather than through formal notice-and-comment rulemaking — is the kind of arbitrary reversal courts routinely enjoin.
Second, and more fundamental: under the Supreme Court’s West Virginia v. EPA major questions doctrine, agencies cannot resolve major policy questions without clear congressional authorization. Extending US export controls from physical goods to network-layer compute access is precisely the kind of major question that doctrine catches. An attorney at Baker McKenzie told The Information it is “widely acknowledged” within the export-control bar that Commerce cannot enforce a remote-access regulation under existing law — the department’s traditional authority covers the transportation of physical goods, not network connections.
That is what the Remote Access Security Act (RASA, H.R. 2683) exists to solve. The bill would amend the Export Control Reform Act of 2018 to add “remote access” as a separately authorized category alongside export, reexport, and in-country transfer — giving BIS explicit statutory authority to license network-layer compute access regardless of whether any hardware moves. It passed the House on January 12, 2026, by a striking 369-22 bipartisan vote. The Senate companion (S. 3519), introduced by Sens. Dave McCormick and Ron Wyden, sits in the Banking Committee without a scheduled vote. Legal analysts at Freshfields assess RASA has a meaningful chance of becoming law either standalone or as an NDAA amendment.
An alternative bill, the Chip Security Act (H.R. 3447), takes a hardware approach: requiring every covered export chip to carry embedded location-verification firmware that continuously reports where the device physically sits. It passed the House Foreign Affairs Committee in March but has not received a floor vote — and Nvidia and the Information Technology Industry Council have argued the requirement would undermine foreign buyers’ confidence in US chips.
Enforcement aggressive on paper, contradictory in practice
The draft rule does not arrive in a vacuum. BIS has spent 2026 building one of the most aggressive enforcement records in its history — while simultaneously making decisions that reduce its leverage.
On the aggressive side: May 31 offshore-subsidiary guidance closed the loophole letting Chinese-headquartered entities buy chips through subsidiaries in non-restricted jurisdictions; Nvidia deployed field compliance teams across Southeast Asia and cut its Asian buyer whitelist by more than half; and on August 28 BIS opened its first-ever enforcement investigation of a freight forwarder — Apex Logistics, a Kuehne+Nagel subsidiary — over allegedly falsified classification codes on 47 Nvidia server shipments destined for China.
On the contradictory side: the BIS Affiliates Rule, which automatically extends chip restrictions to entities at least 50 percent owned by listed Chinese parties, was suspended until November 2026 as part of the US-China trade truce. More than 100 Chinese entities approved for Entity List designation — including DeepSeek and memory-maker ChangXin — have not been added since October 2025. CSIS’s Philip Luck described the pause as “unprecedented,” longer than any comparable enforcement gap in the past decade. Taiwan’s indictments of nine people over 130 smuggled B300 servers this week underscored how physical channels remain active even as legal channels are debated.
What the rule can — and cannot — accomplish
There is one more layer the September timeline obscures: even if RASA passes and the rule takes effect, the specific harm it targets has already occurred. Kimi K3’s weights — all 2.8 trillion parameters, 1.56 terabytes across 96 shards — are publicly available on Hugging Face, downloaded, mirrored, and deployed on hardware far beyond the reach of US sanctions. The compute that produced them has been spent. No legal architecture Washington builds now can retrieve what already passed through the gap.
That is not an argument against closing the loophole — it will otherwise enable the next generation of training runs, and the generation after that. It is an argument for precision about what a rule can do. The September consultation will produce industry objections; a rule issued without RASA’s statutory foundation gives every affected company a ready-made theory for an immediate injunction. Commerce must now decide whether to wait for the Senate, issue a rule it knows is vulnerable, or revive the know-your-customer due-diligence approach it inherited and chose to ignore.
Representative John Moolenaar, whose Select Committee on China has tracked the issue for two years, framed the stakes plainly: Chinese firms’ offshore compute access is the mechanism that turned export controls from a meaningful constraint into a paper wall. The September draft will test whether Commerce can paper over that wall with a rulemaking — or whether it needs Congress to hand it the tools first.
Sources
- [1] https://www.techtimes.com/articles/325957/20260829/commerce-drafts-ai-chip-rule-loophole-it-created-rescinding-biden-know-your-customer.htm
- [2] https://www.tomshardware.com/tech-industry/policy/new-us-export-controls-reportedly-target-chinese-access-to-remote-ai-servers-trump-admins-cut-down-ai-diffusion-rule-could-be-shared-with-industry-as-soon-as-september
- [3] https://www.theinformation.com/articles/trump-administration-working-ai-rule-curb-chinas-remote-access-chips
- [4] https://www.cnbc.com/2026/08/19/china-ai-nvidia-chips-us-export-controls.html