How does Moonshot's approach differ from the chip smuggling we've often heard about before?
The key difference is legality. Chip smuggling refers to physically transporting export-controlled chips into China, which directly violates export control rules and constitutes clearly illegal activity. Moonshot's case is entirely different — according to expert explanation, as long as Moonshot itself doesn't directly purchase or possess the chips, and the chips remain physically in Thailand at all times, with Moonshot simply paying to use those chips' computing power, this practice isn't illegal under the literal definition of current rules.
This is also why this incident is described as a "loophole" rather than a "violation": smuggling deals with "how to catch behavior that's already illegal," while remote access deals with "whether current rules even cover this way of acquiring compute" — the latter is a problem at the level of rule design, not enforcement, which is also why the fix is legislation (like the Remote Access Security Act), not stronger enforcement effort.
Are all 31 planned large data centers across the three Southeast Asian countries built specifically to serve this kind of export-control evasion?
The reporting doesn't argue this conclusion — a more accurate understanding is that this data center construction boom and the rise of the remote-compute-access business model happen to overlap significantly in timing and geography, but that doesn't mean the purpose behind building all these data centers is to serve export-control evasion demand. Southeast Asia has itself been a popular region for global data center investment in recent years, for reasons including relatively low land and power costs, relatively neutral geopolitical risk, and the ability to simultaneously serve rapidly growing regional AI demand — factors that have nothing to do with export control issues in themselves.
A more reasonable reading is that this region already had commercial incentives for developing a data center industry, and the remote-access business model that evades export controls happens to be able to take advantage of this existing infrastructure trend, rather than this construction boom being entirely driven by this specific demand. This is also why precisely determining "what share of Southeast Asian compute capacity is actually being used to evade export controls" is itself a very difficult question with no clear answer currently.
If the Remote Access Security Act passes, can it actually solve this problem?
This legislation itself addresses the gap at the level of rule definition — treating "remote access" itself as an export event would, in principle, bring this kind of activity, currently falling completely outside the scope of regulation, back under oversight. But even if this legislation passes and takes effect, actual enforcement still faces a more fundamental challenge: how does US jurisdiction actually extend into data centers in Thailand or Malaysia that are, in themselves, operating entirely legally?
This involves the complexity of cross-border enforcement — the US can't directly send inspectors to audit a data center in Thailand; it can only rely on disclosure obligations within the chip supply chain itself (like requiring Nvidia or cloud service providers to report customer identity and geographic location), or use diplomatic channels to request local government cooperation on audits. This means that even if the rule itself gets amended, whether it can actually be enforced effectively still depends on whether an entire cross-national coordination mechanism can be built — which is also why the Compute Governance policy domain often needs to address both domestic legislation and international coordination simultaneously; amending domestic regulation alone is often insufficient to fully close this kind of cross-border loophole.
If Kimi K3 can train performance competitive with US frontier models, does that mean compute controls have basically failed to slow China's AI progress?
That inference may extend the implications of a single case too far. This specific Kimi K3 case genuinely shows that at least one Chinese company acquired advanced compute that should have been controlled through a remote-access loophole, but that's not entirely the same as "compute controls have failed for China's AI industry overall" — the remote-access model itself has limitations: it requires payment, requires intermediation through a cloud service provider, and its scale and stability may not match directly owning the hardware. And as legislation like the Remote Access Security Act gradually gets put in place, this channel itself may also gradually get tightened.
A more accurate understanding might be that compute controls are currently in a state of "partial leakage" rather than "total failure": controls genuinely have raised the difficulty and cost of Chinese companies acquiring top-tier compute, but haven't fully blocked it, and remote access is currently one of the main leakage channels. This also echoes a core point in this site's Compute Governance entry: policy research institute reports generally find that export controls alone aren't sufficient to fully prevent a specific country from developing advanced AI capability, which is why some researchers argue compute governance needs to be paired with other tools like compute thresholds to form a multi-layered governance architecture.
The US has imposed export controls on Nvidia's most advanced AI chips, aiming to prevent China from acquiring the compute needed to train frontier models — but according to the latest reporting from August 2026, these controls are being sidestepped through a structural loophole: Chinese AI companies don't need to buy the chips, and don't need the chips to physically enter China — they can simply pay to remotely access the computing power of these chips through data centers in Southeast Asia, circumventing current controls. The core of this loophole is that current US export control rules govern who buys a chip, where it ships, and who physically possesses it — they don't cover who pays to remotely use a machine sitting in another country.
This loophole surfaced in July following the release of a specific model. Less than a week after Chinese startup Moonshot AI released its Kimi K3 model, White House official Michael Kratsios publicly accused the company of accessing Nvidia's export-restricted GB300 chips through a facility in Thailand. The GB300 belongs to Nvidia's latest-generation Blackwell architecture high-end chips, which under current rules cannot be sold directly to Chinese companies. According to Cassia King, senior researcher on the Compute Policy team at the Institute for AI Policy and Strategy, speaking to CNBC, this kind of access is legal under current rules as long as Moonshot isn't directly purchasing and owning the physical hardware — "the US system controls physical AI chips. It does not cover remote access to those chips."
This loophole isn't an isolated case involving a single company. According to reporting, Chinese tech giants including ByteDance, Alibaba, and Tencent have reportedly accessed Nvidia chip computing power through facilities in Malaysia, Thailand, and Japan. This also explains part of the backdrop behind Southeast Asia's recent data center construction boom: according to data compiled by DC Byte, there are currently 31 planned data centers exceeding 100 megawatts across Malaysia, Indonesia, and Thailand, compared to just two today — a remarkable growth rate. Michelle Nie, a visiting fellow in technology and national security at think tank Center for a New American Security, told CNBC this loophole is threatening the strategic goal the US originally intended to achieve through chip export controls.
Congress hasn't been unaware of this problem. The Remote Access Security Act, aimed at closing this gap by treating remote access itself as an export event, passed the House of Representatives in January 2026, but as of now still awaits Senate deliberation and the drafting of implementing rules. Even if this legislation eventually passes, how to actually enforce US export control rules within another jurisdiction (like Thailand or Malaysia) remains an unresolved enforcement puzzle in itself — after all, these data centers don't violate local law where they operate, and extending US jurisdiction to overseas compute-rental arrangements is an entirely different tier of legal and diplomatic challenge.
For readers assessing the actual effectiveness of Compute Governance policy, this incident offers a concrete, checkable case illustrating the enforcement gap export controls currently face: the policy was designed to control who can acquire the compute needed to train frontier models by controlling the physical flow of chips, but when chips can stay put and have their computing power sold overseas as a cloud service, the physical anchor point of the control gets bypassed. This also directly echoes a core observation in this site's compute governance entry: enforcement-level loopholes like chip smuggling and third-country transshipment limit the actual effectiveness of export controls as a standalone tool. For readers assessing the actual compute foundation behind Chinese frontier AI models like Kimi K3, understanding this loophole matters too — a model's performance may not fully reflect the scale of compute a company "should" be able to access under the existing regulatory framework, but rather the scale of compute it can actually access given the current gap in regulatory enforcement. That gap is exactly the central battleground where compute governance policy will keep being adjusted over the coming years.