Hero image for "The Cloud Loophole Is the Export Control Regime's Biggest Unresolved Problem"

The Cloud Loophole Is the Export Control Regime's Biggest Unresolved Problem


A White House official accused a Chinese AI company of training on Nvidia's most restricted chips last month. The chips were in Thailand. The access was remote. And according to U.S. export control law, it was entirely legal.

That's the state of semiconductor sanctions in August 2026.

What the Law Controls — and What It Doesn't

The U.S. export control regime was built around a physical object: the chip itself. Restrict the hardware, restrict the capability. It's a logical framework for a world where compute meant owning a server rack.

That world no longer exists.

According to CNBC, Moonshot AI — a Chinese firm — reportedly accessed Nvidia GB300 computing power through a data center in Thailand less than a week before releasing its Kimi K3 model in July. White House official Michael Kratsios named the company publicly. Cassia King, a senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy, told CNBC the arrangement was legal "so long as Moonshot isn't actually buying and owning the physical hardware directly." The export control regime, she explained, "controls physical AI chips. It does not cover remote access to those chips."

This is a structural gap, not an enforcement failure. BIS didn't miss something — the law simply doesn't reach what Moonshot did. The chips never crossed into China. No violation occurred.

The downstream effect is visible in the model benchmarks. DeepSeek, Alibaba, and Moonshot have all released AI systems in recent months that have scored competitively on performance evaluations. Industry analysts attribute part of that progress to access to advanced compute through overseas cloud providers — exactly the channel the current regime doesn't touch. The AI race between the U.S. and China is, as Reuters has framed it, at a pivotal point as Chinese open-weight models gain against OpenAI and Anthropic.

Washington's Response: Pick Sides, Then Figure Out the Rules

The administration's near-term answer to the loophole problem is geopolitical rather than technical: force third countries to stop hosting the workaround.

Reuters reported on August 14 that the U.S. is preparing to send a letter to 35 signatories of its "AI Opportunity Statement" warning them they will be excluded from the U.S.-led Pax Silica coalition if they also join China's competing framework. The draft letter, prepared by the State Department, targets countries that have expressed a desire to align AI cooperation with Washington — including Kazakhstan, which has joined both coalitions and sits on significant critical mineral reserves.

The logic is straightforward: if Southeast Asian data centers can't host Chinese firms' training runs without losing U.S. partnership access, the Thailand workaround gets more expensive. But the mechanism is diplomatic pressure, not law. A country that decides the Chinese market matters more than Pax Silica membership can keep hosting those workloads. Thailand isn't named in the Reuters reporting as a coalition member facing this ultimatum.

Meanwhile, U.S. legislation to regulate remote cloud access to controlled technology is reportedly under discussion, according to CNBC — but "under discussion" is doing a lot of work in that sentence. Defining what constitutes controlled "access" to a chip versus ordinary cloud computing is genuinely hard. A rule broad enough to catch Moonshot's training runs could also sweep in legitimate international cloud customers. The jurisdictional questions alone — regulating what a Thai data center does with its own hardware — would require either extraterritorial authority or treaty-level cooperation.

Beijing Is Building Its Own Counterpressure

While Washington debates how to extend its reach, Beijing has been systematically building legal architecture to make compliance with U.S. controls more costly for companies operating in China. Foreign Policy reports that Beijing's countermeasures now include six distinct instruments: the Export Control Law (2020), the Unreliable Entity List (2020), the Anti-Foreign Sanctions Law (2021), the Blocking Rules (2021), the Counter-Extraterritorial Regulation (2026), and the Supply Chain Security Provisions (2026). The 2026 additions are specifically designed to penalize companies for complying with foreign sanctions and export controls.

The practical effect: a Western company that restricts its China operations to comply with U.S. export controls now faces potential legal exposure under Chinese law for doing so. That's not a hypothetical — it's the explicit design of the framework, as Foreign Policy details, built to undercut Western policies of extraterritoriality whereby the U.S. extends sanctions to foreign firms doing business with primary sanctions targets.

The sanctions regime and the counter-sanctions regime are now in direct legal conflict for any multinational operating across both jurisdictions. This dynamic has a hardware supply chain dimension too: Nvidia's own efforts to secure U.S.-based packaging capacity — including a reported $1.5 billion deal with Amkor Technology announced in July — reflect how seriously the company is treating the need to onshore critical production steps, even as the export control perimeter around its most advanced chips keeps developing holes.

The Milestone to Watch

The legislative timeline on cloud access regulation is the number that matters most right now. If Congress can't define "controlled remote access" in statutory language before the next generation of Chinese AI models trains on GB300-equivalent compute through Southeast Asian intermediaries, the physical chip export ban will have functioned primarily as a routing problem — one that took Chinese firms roughly 18 months to solve.

Watch for Commerce Department rulemaking proposals on cloud compute controls this fall. If nothing moves before year-end, the gap between the export control announcement and export control reality will have widened again — and the PowerPoint will have drifted further from the silicon.