The chip didn’t cross the border
The Invisible Journey
Control Still Lies with the Hardware

Reported does not mean proven
Moonshot Under Accusation
Moonshot’s access to the GB300 chips stems from an accusation made by Michael Kratsios following the launch of Kimi K3. The public record reviewed provides no contract, usage log, machine inventory, or confirmation from Moonshot. To state that the company certainly used these chips would therefore go beyond the available evidence.
ByteDance and Aolani

From Product to Use
Selling a Chip, Renting a Function
Sovereignty is shifting
The point of control shifts from the port to the customer account. It is necessary to know the user’s true identity, their affiliated companies, the destination of the workload, and sometimes the trained model. This oversight is more complex than a serial number, because services can be resold and corporate identities can multiply.

Asia is becoming the interface
Thailand, Malaysia, Japan
Thirty-one Mega Projects
The gap isn’t emerging in a stagnant market; it’s opening up just as Southeast Asia is building the global computing highway. The more capacity increases, the more a system focused on a few physical shipments risks missing the bigger picture.

A bill is pending in the Senate
What H.R. 2683 Would Do
The Remote Access Security Act, H.R. 2683, would extend the Export Control Reform Act to cover remote access. The bill defines such access as a foreign person’s access to an item under U.S. jurisdiction via a network connection, the Internet, or a cloud service from a location other than where the item is physically located.
Passed Here, Blocked There

Even if passed, the law would not be enough
Authority Is Not the Rule
The Threshold Problem
Should the regulation target a specific type of chip, a certain amount of computing power, a lease duration, an AI model, or the customer’s identity? Each answer creates its own loophole. A hardware threshold can be circumvented through aggregation. A usage threshold requires an understanding of a workload that the provider does not always clearly see.
The challenge isn’t to write the word “cloud” into the law; it’s to transform a strategic intention into a measurable, enforceable, and challengeable obligation. Without this precision, the new frontier would become an administrative slogan rather than an actual control.

The Rule That Existed and Then Disappeared
The January 2025 Framework
The AI Diffusion Rule, published on January 15, 2025, was specifically intended to limit China’s access to advanced chips and computing power via third countries. It divided the world into categories, established a framework for validated data centers, and proposed restrictions on the cloud and the sizes of highly advanced models.
The May Revocation

The Withdrawn Replacement
March 2026, yet another draft
In late February 2026, the Department of Commerce had sent a draft titled “AI Action Plan Implementation” to other agencies. Reuters reports that it envisaged conditions related to large volumes of chips, including security guarantees or investments in U.S. data centers for certain exports.
A Policy of Stop-and-Go

The Trump Paradox
Exporting the Tech Stack, Protecting the Lead
The second Trump administration is pursuing two conflicting objectives: spreading the American technology stack to partners and preventing that spread from fueling China’s most advanced capabilities. One requires speed, market access, and trust. The other requires control, verification, and sometimes denial.
Credit and Responsibility
A strategy isn’t strong simply because it makes loud claims. It is strong when its various parts stop contradicting one another.

Know the customer—truly
KYC for computing
Closing the gap requires a form of “Know Your Customer” tailored to the cloud. The provider should identify the actual entity, its owners, its affiliated companies, and perhaps certain sensitive uses. The “Diffusion” rule’s validated data center programs were already moving in this direction.
But a form isn’t enough. Corporate structures can hide a beneficiary, resellers can split access, and a legitimate customer can rent on behalf of a third party. Verification must therefore combine identity, behavior, traceability, and the right of recourse—without assuming that every anomaly proves hostile intent.
Compliance Comes at a Cost
“Know your customer” must not become “suspect the whole world.”

Allies are not subsidiaries
The sovereignty of host countries
Don’t Hand the Market Over to Beijing

National security is not just for show
Why Chips Matter
Advanced accelerators enable the training and operation of powerful AI systems. U.S. officials fear that these capabilities could support military, intelligence, or surveillance applications. The Congressional Research Service places these controls within a broader policy framework aimed at addressing China’s military-civil fusion and U.S. technological leadership.
Precision vs. Panic
National security gains strength when it distinguishes a documented threat from nationality, and a sensitive use from a mere commercial presence. Otherwise, it becomes unfounded fear—easy to circumvent and impossible to defend to partners.

What the Report Does Not Prove
No public inventory
No General Illegality Established
Cassia King believes that Moonshot’s access would be legal as long as the company neither purchases nor owns the hardware. Aolani claims compliance. The Department of Commerce and the BIS did not respond to CNBC. Without a clear general rule on remote access and without a published enforcement decision, the term “circumvention” primarily describes the failure of a policy objective, not necessarily an established violation.

What Would Truly Close the Loophole
A Framework Rather Than a Slogan
A Stable Policy Framework

The border has become an identifier
The American Choice
The Verdict After the Evidence
The next American frontier may not be on a map. It will be in the “authorized user” box.
Columnist’s Transparency Box
Editorial Position
Methodology and Sources
This text respects the fundamental distinction between verified facts and interpretive analysis. The methodological rule is consistent: factual information is published only if it is supported by a verifiable source, and the sources actually used in this article are listed under “Sources,” never here.
When an article cites statistical, economic, or geopolitical data, it is sourced from data-producing institutions (intergovernmental organizations, central banks, national statistical institutes), and the specific institution is listed under “Sources.”
Nature of the Analysis
ANALYSIS: The Asian Cloud Is Pushing the Boundaries of AI Chips
This content was created with the help of AI.