AI

Washington controlled the chips. Chinese AI labs rented the compute instead.

The Bureau of Industry and Security has started systematically reviewing a route into Nvidia’s best silicon that never required smuggling: Chinese firms renting time on hardware parked in Malaysia, Singapore and Japan. One think-tank estimate puts the leakage at 60% or more above what the export controls alone would permit.

N Noah · The Sharp Brief · August 8, 2026 · 4 min read

For four years American chip policy has been an inventory problem. Count the Nvidia accelerators, restrict where the boxes ship, and China’s frontier labs run short. The Bureau of Industry and Security — the Commerce Department arm that normally chases smugglers — is now reviewing a route that never required smuggling at all: Chinese AI firms renting time on Nvidia hardware that sits in somebody else’s country.

Bloomberg reported Friday that BIS has begun looking systematically at those legal offshore compute-rental arrangements, with Reuters and MarketScreener carrying the same account. What set it off was not a tip-off. It was capability. A run of Chinese releases made it plain the labs were training on exactly the class of hardware the rules were written to withhold — Alibaba shipped Qwen3.8-Max on August 3 at 2.4 trillion parameters with open weights promised this coming week, and ByteDance is pre-training at ten trillion.

The size of the gap is the part worth sitting with. The Institute for AI Policy and Strategy estimates offshore rental is lifting China’s effective access to advanced US compute by at least 60% in 2026 above what the export controls alone would permit. Bloomberg’s reporting sketches the shape of it: Alibaba reaching Nvidia chips physically located in Malaysia through Megaspeed International, a Singapore firm already under US investigation for possible chip diversion. Renting is not shipping. Nothing in the export-control statute currently says otherwise.

The controls were written for boxes, not sockets

Washington has been patching toward this for a year without closing it. In May, Commerce issued guidance that license requirements follow China-headquartered entities even when those entities operate outside China. Nvidia sent field compliance teams to physically inspect data centres in Singapore, Malaysia and Japan, then cut its Asian buyer whitelist by more than half. And in January the House passed the Remote Access Security Act 369–22 — a bill that would amend the Export Control Reform Act so controls can reach remote access rather than only physical export.

That bill is still sitting. The Senate companion, S. 3519 from Dave McCormick and Ron Wyden with Tom Cotton and Chris Coons cosponsoring, went to Banking in December and has not moved since. Which leaves BIS reviewing a practice it may not currently have the authority to stop. The agency’s options are a novel enforcement theory under existing law, or waiting on Congress.

Our take: Export controls have been scored on the wrong metric for two years. “Chips shipped” is auditable and satisfying; “compute reached” is what actually determines who trains what. A 60% divergence between those two numbers is not a leak to be plugged — it is a second channel operating at scale, in the open, legally. The uncomfortable part for policymakers is that closing it means regulating cloud rental itself, which lands on American hyperscalers’ overseas capacity every bit as hard as it lands on a Singaporean intermediary.

What to watch

The controls did what they were written to do. They stopped the chips from moving. Nobody wrote the sentence that stops the work from moving to the chips — and for a year now, that has been the sentence that mattered.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook (PDF) lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.