Explainer

How Washington Wants to Control Not Just the Chip, but Who Logs Into It

Commerce is drafting a rule to stop Chinese firms from renting U.S. AI chips through data centers in Thailand and Singapore, and lawyers say it may lack the legal authority to enforce it.

Aerial view of a large data center roof with extensive rows of cooling towers and backup generators
The roof of a data center, showing cooling towers and backup generators. Rsparks3 · CC0 · via Wikimedia Commons

U.S. export rules can stop an Nvidia server from being shipped to Beijing. They have had a harder time stopping someone in Beijing from renting time on a similar server sitting in a data center in Bangkok or Singapore. The Commerce Department is now drafting a rule meant to close that gap, according to trade press tracking the measure, with a draft that could be shared with industry groups as soon as September.

The shift matters because it would move export enforcement from ports and shipping manifests to cloud logins and data-center leases. That puts new compliance weight on Nvidia and on the U.S. and Asian cloud providers whose data centers have become the workaround.

How Chinese Firms Have Been Renting Around the Ban

Existing controls restrict the sale and shipment of advanced Nvidia chips to China. They say much less about who is allowed to log into those chips once they are installed somewhere else, according to Forbes reporting on the gap. Chinese hyperscalers including ByteDance, Alibaba and Tencent have reportedly tapped Nvidia computing power by accessing data centers in other Asian countries, including Thailand, Malaysia and Japan.

One case cited in that reporting involves ByteDance accessing compute in Malaysia through Aolani, a Singapore-headquartered cloud provider; Aolani has said its services are in full compliance with applicable regulations. A separate case involves Moonshot AI, which Michael Kratsios, director of the White House Office of Science and Technology Policy, alleged on July 22 had trained its Kimi K3 model using Nvidia GB300 servers based in Thailand.

What the Draft Rule Would Reportedly Require

The core of the draft rule, as described by Forbes and BigGo Finance, would target Chinese companies' remote access to advanced Nvidia chips housed in data centers in third countries such as Thailand and Singapore. In effect, it would treat cloud access to a controlled chip the same way current rules treat a physical shipment: as an export that can require a license.

That is a change from how export enforcement has worked. Chip export controls have historically focused on where hardware physically goes. A rule built around remote access would instead focus on where the user is when they connect to it, regardless of where the chip itself sits.

Whether Commerce Has the Legal Authority to Enforce It

Export-control lawyers have raised doubts about whether the Bureau of Industry and Security can act on this without new legislation. Advisory opinions BIS itself issued between 2009 and 2014 held that cloud providers are not exporters and that no export occurs so long as controlled hardware stays in place and is only accessed over a network, according to reporting on those opinions. One attorney told The Information it is widely acknowledged within the export-control bar that Commerce cannot enforce a remote-access regulation under existing law.

Congress has a bill meant to fix exactly that gap. The Remote Access Security Act, H.R. 2683, would amend the Export Control Reform Act to give BIS explicit authority over remote access, which the bill defines as access by a foreign person through a network connection, including a cloud computing service. The House passed it 369-22 on January 12, 2026. The Senate received it the next day and referred it to the Banking, Housing and Urban Affairs Committee, where it remains without a scheduled vote. A companion bill, S. 3519, was introduced by Senators Dave McCormick of Pennsylvania and Ron Wyden of Oregon.

What It Means for Chipmakers and Cloud Providers

Ahead of any new regulation, Nvidia has already built its own customer-vetting system across Asian markets, cutting more than half of its previously approved Asian buyers from an internal whitelist, with neocloud providers — the firms whose business is renting out AI compute — affected most, according to Forbes. Company staff have reportedly visited data centers to verify that customers are who they claim to be.

If a remote-access rule is finalized, that compliance burden would extend further down the chain, to the data-center operators and cloud providers actually hosting the chips. Latham & Watkins, writing about the broader remote-access legislation, advises companies to review cloud contracts, screen customers and suppliers, and add geo-blocking, identity checks and audit logging, and to plan for potential licensing delays.

This would not be Commerce's first attempt to put verification duties on cloud providers. A separate 2024 proposal would require U.S. infrastructure-as-a-service providers to verify foreign customers' identities and report to BIS within 15 days when a foreign customer trains a large AI model with potential for malicious cyber use, according to a summary from Skadden. Comments on that proposal closed in April 2024.

What Happens Next

Commerce is reportedly planning to circulate its draft rule to industry groups as soon as September, though it has not been formally published. Whether the rule follows the standard notice-and-comment rulemaking process, and whether it takes effect before or after the Senate acts on the Remote Access Security Act, is not yet clear from available reporting.

The new rule would also arrive alongside a broader reset of chip export policy. Commerce formally rescinded the Biden administration's AI Diffusion Rule in May 2025, which the agency said would have stifled American innovation and set back relations with dozens of countries assigned to lower access tiers. BIS said at the time it would issue a replacement rule in the future. That replacement and the remote-access rule would together govern two different questions: what is allowed to leave U.S. shores, and who is allowed to log in once it has.

The Technology Desk

Editorial Staff

More from Technology