August 30, 2026:


The Trump administration is preparing a rule that would make it illegal to rent Nvidia GPU computing time to Chinese AI companies through servers in Thailand and Singapore — and the lawyers who follow US export controls most closely say the Commerce Department almost certainly lacks the statutory authority to enforce it. According to Commerce draft circulates in September, Commerce may share the draft with industry trade groups as early as September, a procedural step that signals a formal rulemaking commitment rather than exploratory review. What it does not signal is a clear legal path to enforcement. An attorney at Baker McKenzie, one of the firms whose clients navigate these restrictions daily, told The Information that it is “widely acknowledged” within the export-control bar that Commerce cannot enforce a regulation on remote access to chips under existing law — Baker McKenzie’s legal assessment that the department’s traditional authority covers the transportation of physical goods, not network-layer compute access.
The reason has nothing to do with the merits of the national security goal. It has to do with what the word “export” has meant under US law since 2009, and with the fact that the Trump administration spent the first 18 months of its term making the gap worse before deciding to close it.
The legal gap at the center of this story was not created by oversight. It was created by BIS 2009 cloud computing opinion — and BIS advisory opinions issued in 2011 and 2014 — that gave the cloud-computing industry a foundational legal assurance: when a cloud provider makes computing capacity available to a foreign customer, and the hardware never moves, no export has occurred. The provider is not the exporter; the user never receives a “release” of a controlled item in the sense that 15 CFR § 734.2 requires. That holding made the Software-as-a-Service industry globally viable. It also, as a direct architectural consequence, established that a Chinese AI lab sending training jobs over the internet to an Nvidia H100 cluster in Bangkok is not triggering US export controls — because the chip never crosses a border in a way the regulation recognizes.
Those advisory opinions are not policy preferences. Under administrative law principles, they are agency commitments that bind BIS itself. Reversing them through enforcement action against a specific company — rather than through a formal notice-and-comment rulemaking — would expose BIS to an immediate legal challenge that it would be unlikely to survive, particularly under the West Virginia v. EPA ruling, which requires clear congressional authorization for major policy questions that agencies were not historically given authority to resolve. A rule requiring Chinese AI companies to obtain licenses before accessing GPU compute through an offshore data center is precisely the kind of major question the Court’s doctrine was designed to catch.
This is the problem the Remote Access Security Act exists to solve. RASA’s text in Congress — House bill H.R. 2683 — passed the House on January 12, 2026, by a 369-22 bipartisan vote that reflected something genuinely rare in the current Congress: near-consensus on a national security technology question. The bill would amend Sections 4812 and 4815 of the Export Control Reform Act of 2018 to add “remote access” as a separately authorized category alongside export, reexport, and in-country transfer — giving BIS explicit statutory authority to license the activity the advisory opinions currently place outside its reach. Senate companion legislation (S. 3519), introduced by Sens. Dave McCormick of Pennsylvania and Ron Wyden of Oregon, is pending in the Senate Banking Committee without a scheduled vote, per McCormick’s RASA press release.
Until the Senate acts, Commerce is attempting to do through regulation what it may only be able to do through statute.
There is a specific reason the loophole that this rule is trying to close is wider today than it would have been without the Trump administration’s own early decisions — and it has nothing to do with the Biden-era AI Diffusion Rule that the White House rescinded in May 2025.
The Biden administration, in its final weeks, established the Foundry Due Diligence Rule: a requirement that cloud providers and data-center operators verify who their end users actually are before provisioning advanced AI compute. Trump will not enforce rule — the Trump administration inherited that rule, declined to enforce it, and publicly said it would not do so. The rule would have imposed a know-your-customer obligation on the infrastructure layer — meaning a Thai data-center operator serving inference jobs for a Beijing-based AI company would have needed to verify and document who was accessing its Nvidia cluster.
The consequence is not incidental. In the 18 months between the Trump administration’s decision not to enforce the Foundry Due Diligence Rule and today, Chinese AI labs used exactly the access the rule would have required them to disclose to train models that are now globally distributed. Alibaba bankrolled Kimi K3 — Moonshot AI, backed by Alibaba, trained Kimi K3, a 2.8-trillion-parameter, open-weight Mixture-of-Experts model, on a computing cluster of roughly 20,000 Nvidia chips supplied through Alibaba’s cloud infrastructure. The IAPS compute-gap research brief estimated that offshore compute-rental arrangements could be boosting China’s effective access to advanced US compute by at least 60 percent in 2026 relative to what chip export controls would otherwise permit.
The Trump administration is now drafting a rule to prevent what the rule it chose not to enforce was designed to prevent. The legal tools it has to work with are more limited than the ones it inherited.
The immediate catalyst for moving from review to rulemaking is the controversy over Kimi K3, which Moonshot AI unveiled at the World Artificial Intelligence Conference in Shanghai on July 16, 2026. The model’s benchmark performance — ranking near the top of global AI capability assessments and outperforming several leading American systems on coding and web-development tasks — set off a brief but severe market reaction, wiping an estimated $3.3 trillion market loss in semiconductor market value during its release week.
On July 22, White House Office of Science and Technology Policy Director Michael Kratsios posted on X July 22 publicly accusing Moonshot of training Kimi K3 using Nvidia GB300 Blackwell processors accessed through servers in Thailand — the most capable AI accelerators Nvidia manufactures and among the most tightly restricted for Chinese buyers. Kratsios further alleged that Moonshot built a “sophisticated internal platform” to extract capabilities from US AI models at scale through a technique called knowledge distillation — a method of training one model to mimic the outputs of another. Anthropic reported unauthorized queries to its Fable model that it attributed to the same effort.
The allegations remain unverified. A person familiar with Moonshot’s procurement confirmed to multiple outlets that the company has a channel for accessing Blackwell chips through Southeast Asian intermediaries, but declined to specify whether this constitutes a rental arrangement — generally permissible under existing rules — or a direct purchase, which would breach US restrictions. Moonshot has not publicly addressed either allegation. Nvidia stated that it complies with all export control regulations and enforces compliance across its sales channels.
What is independently confirmed is a related but distinct arrangement: Bloomberg’s investigation on July 31 established that Moonshot trained Kimi K3 on approximately 20,000 Hopper-generation Nvidia chips supplied through Alibaba’s cloud infrastructure — a compute-rental arrangement that existing export controls were not designed to reach. Alibaba disputed that the chips were H200s — the most capable Hopper-generation accelerators — but did not deny the arrangement’s existence.
Beyond Moonshot, the pattern is widespread. INF Tech Tencent GPU deals: INF Tech, a Shanghai-based startup, accessed approximately 2,300 Blackwell GPUs through a rental agreement with an Indonesian telecommunications company in a deal valued at roughly $100 million. Tencent secured access to approximately 15,000 Blackwell processors through Japanese cloud provider Datasection in contracts worth approximately $1.2 billion. ByteDance, Alibaba, and Tencent had all reportedly accessed Nvidia compute through Southeast Asian and Japanese data centers under similar arrangements.
The specific statutory problem the draft rule faces is worth understanding in precise terms, because the scale of the policy debate can make the legal gap seem like a technicality. It is not.
When a Chinese AI company sends a training job to a GPU cluster in Thailand, the sequence looks like this: training data and model configuration travel via the internet to the data center; the Nvidia GPU processes the computation; the updated model weights are returned. The GPU stays in its rack. The chips do not cross a border in any physical sense. Under 15 CFR § 734.2, an “export” requires the “actual shipment, transfer, or release” of an item to a foreign party. BIS 2009 cloud computing opinion concluded that providing remote access to a computing resource is not a release of the underlying hardware — the provider is not the exporter, and the user who merely accesses compute has not received the controlled item.
RASA solves this by bypassing the definition entirely. RASA’s text in Congress adds “remote access” as a separately authorized category in the Export Control Reform Act, allowing BIS to require a license for using a network connection to access a US-jurisdiction item from a restricted location — regardless of whether any physical transfer occurred.
The Chip Security Act (H.R. 3447) takes a different approach. Rather than redefining what counts as an export, it would require every covered chip destined for export to carry an embedded firmware- or hardware-level location-verification mechanism that continuously reports where the device physically sits. Chip Security Act’s bill text — the bill passed the House Foreign Affairs Committee with bipartisan support in March 2026 but has not received a full House floor vote. Under the Chip Security Act, a Thai data center’s Nvidia cluster would continuously report its physical location; BIS could verify who was accessing it and whether that access pattern was consistent with the end-user certification on file. Nvidia and ITIC opposition — Nvidia and the Information Technology Industry Council have argued the requirement would undermine foreign buyers’ confidence in US chips.
Without one of these two statutes — or something equivalent — the draft rule Commerce is preparing for September faces the legal vulnerability Baker McKenzie identified.
Freshfields RASA legislative analysis — Legal analysts at Freshfields assess that RASA has a meaningful chance of becoming law either in its current form or as an amendment to the National Defense Authorization Act for Fiscal Year 2027. The 369-22 House margin substantially increased the bill’s legislative momentum compared to an earlier version that stalled in 2024.
The draft rule does not arrive in an enforcement vacuum. BIS has spent 2026 building one of the most aggressive chip-enforcement records in its history while simultaneously making decisions that reduce enforcement leverage.
On the aggressive side: the agency issued its BIS May 31 offshore subsidiary guidance, closing the offshore-subsidiary loophole that allowed Chinese-headquartered entities to purchase advanced chips through legally separate subsidiaries in Malaysia, Singapore, and other non-restricted jurisdictions. Nvidia cut its Asian whitelist — Nvidia deployed field compliance teams to physically inspect data centers across Southeast Asia and cut its Asian buyer whitelist by more than half. And as of August 28, BIS probes Apex Logistics — BIS has opened the first-ever enforcement investigation targeting a freight forwarder — Apex Logistics, a Kuehne+Nagel subsidiary — for allegedly falsifying export classification codes on 47 Nvidia server shipments destined for China.
On the contradictory side: BIS Affiliates Rule suspension — the BIS Affiliates Rule, designed to automatically extend chip restrictions to entities at least 50 percent owned by listed Chinese parties, was suspended until November 2026 as part of a US-China trade truce. More than 100 Chinese entities approved for designation by an interagency committee — including DeepSeek and memory chipmaker ChangXin Memory Technologies — have not been added to the Entity List since October 2025, a pause that Philip Luck’s unprecedented gap assessment — Center for Strategic and International Studies’ Philip Luck described as “unprecedented,” longer than any comparable enforcement gap in the past decade.
The pattern is enforcement against illegal smuggling and structural tolerance of legal access channels — with the draft rule representing an attempt to shift the second category into the first, if the statutory authority can be established.
Assume the draft rule is finalized and issued as written, without RASA. The first company subject to it challenges the rule in federal court. Its legal team files two arguments simultaneously.
First: the BIS advisory opinions of 2009, 2011, and 2014 told the entire cloud-computing industry that remote compute provision is not an export event. Reversing those opinions through enforcement rather than formal rulemaking is arbitrary and capricious under the Administrative Procedure Act. Settling this requires a formal notice-and-comment rulemaking — which Commerce is presumably conducting right now, by sharing the draft with industry in September — but any resulting rule would itself face a challenge on the merits.
Second, and more fundamental: under West Virginia v. EPA ruling, agencies cannot make major policy decisions without clear congressional authorization. Extending US export controls from physical goods to network-layer compute access is, as the RASA legislative history makes explicit, exactly the kind of major question Congress recognized it had not previously authorized BIS to resolve. The bill’s sponsors said so directly in Senate floor statements: “under current law, bad actors can train AI models by accessing advanced chips under the jurisdiction of the US, and the Bureau of Industry and Security has no authority to require a license,” according to McCormick’s RASA press release.
A court applying those two arguments does not need to rule on whether the policy is wise. It only needs to rule on whether the agency had the authority. If Baker McKenzie is right that the answer is widely acknowledged to be no, the rule is an expensive delay rather than a solution.
There is one more layer to this story that the September timeline tends to obscure: even if RASA passes the Senate and is signed into law before the rule takes effect, the specific harm the rule is designed to prevent has already occurred.
Kimi K3 model weights release — Kimi K3’s model weights — all 2.8 trillion parameters, 1.56 terabytes of data across 96 shards — are publicly available on Hugging Face. They have been downloaded, mirrored, and deployed on hardware well beyond the reach of US sanctions. The compute that produced them has already been used. Whatever legal architecture Washington builds going forward, it cannot retrieve the output of the compute access that preceded the rule’s drafting.
This is not an argument against enacting RASA or closing the remote-access loophole. Both of those things remain necessary — the loophole will otherwise enable the next generation of training runs, and the generation after that. It is an argument for understanding precisely what this rule can and cannot accomplish, and for not confusing the closure of a regulatory gap with the retrieval of what passed through it.
The administration’s immediate challenge is simpler and more urgent: the September consultation will produce industry objections, and the resulting rule, if issued without RASA’s statutory foundation, will face immediate legal challenge. Commerce will need to decide whether to wait for the Senate, issue a rule it knows is vulnerable, or find an alternative path — such as aggressively enforcing the know-your-customer due-diligence requirements the Biden administration left in place and the Trump administration chose to ignore.
Moolenaar on compute as mechanism — Moolenaar, whose Select Committee on China has tracked this issue for two years, framed the stakes as directly as anyone in Congress. Chinese AI firms’ compute access through offshore data centers is not an abstraction, he said: it is the mechanism that turned export controls from a meaningful constraint into a paper wall.
The September draft will test whether Commerce can paper over that wall with a rulemaking, or whether it needs Congress to hand it the statutory tools first.
No — and that is precisely the problem this draft rule is intended to address. Under BIS cloud advisory opinions from 2009, 2011, and 2014, cloud providers are not “exporters” under the Export Administration Regulations, and making computing capacity available remotely is not an export event. The May 31, 2026, BIS guidance closed the related loophole for direct chip purchases by Chinese-headquartered subsidiaries through offshore entities, but explicitly stated that data centers already operating under prior rental arrangements were not required to stop. As of today, a Thai data center providing Nvidia H100 access to a Beijing-based AI company is operating in a legal gray zone that existing regulations cannot clearly reach.
The legal barrier is structural. BIS advisory opinions bind the agency under administrative law — reversing a 15-year-old agency position through enforcement action rather than formal rulemaking is the kind of arbitrary reversal that courts routinely enjoin. More fundamentally, the Supreme Court’s 2022 West Virginia v. EPA ruling requires that agencies have clear congressional authorization before making major policy decisions. RASA’s legislative history explicitly acknowledges that extending export controls to network-layer compute access is outside BIS’s current statutory authority. A rule issued without that statutory foundation gives every affected company a ready-made legal theory for an immediate injunction. Commerce can issue the rule — but Baker McKenzie’s statutory assessment, widely shared in the export-control bar, is that the rule cannot survive the resulting court challenge.
The Biden administration, in its final weeks, established the Foundry Due Diligence Rule — a know-your-customer requirement obligating cloud providers and data-center operators to verify and document who their end users are before provisioning advanced AI compute. Trump declined to enforce rule — the Trump administration inherited that rule and chose not to enforce it. That decision left data centers in Thailand, Singapore, Malaysia, and Japan free to provision Nvidia GPU access to Chinese AI companies without verifying who was ultimately accessing the compute. In the 18 months that followed, Chinese AI labs including Moonshot AI trained frontier-level models on precisely that compute — and the resulting model weights are now globally distributed and cannot be retrieved. The draft rule Commerce is now preparing would impose similar verification requirements through a different regulatory mechanism, but it faces statutory barriers the Biden-era approach did not face because the Foundry Due Diligence Rule operated under a different legal theory.
The September industry consultation represents the moment when operators can formally shape what the rule covers — and the compliance obligations it imposes. Legal practitioners are currently advising data-center operators per Latham’s data center compliance guidance to: audit all existing compute-provisioning contracts to identify customers whose ultimate parent company may be headquartered in China or another Country Group D:5 nation; implement enhanced know-your-customer screening and geographic IP monitoring for GPU provisioning; document the full chain of title for every Blackwell-generation or Hopper-generation GPU currently in service; and model the business impact of RASA enactment on existing customer relationships. Whether the rule can be enforced without RASA is a legal question — but the compliance preparation is the same either way, because the rule will create uncertainty about past arrangements even if it cannot immediately be enforced on its terms.