TAIPEI, TAIWAN - JUNE 2: A motherboard featuring NVIDIA chips, at the COMPUTEX TAIPEI trade show, in Taipei, Taiwan, on June 2, 2026. COMPUTEX TAIPEI is one of the worldâs largest and most significant trade show, featuring products and services related to latest technologies, drones, data solutions, Artificial Intelligence (AI), supercomputers, applications of semiconductors and more from major international tech firms such as Nvidia, Intel and Foxconn. (Photo by Daniel Ceng/Anadolu via Getty Images)
TAIPEI, TAIWAN - JUNE 2: A motherboard featuring NVIDIA chips, at the COMPUTEX TAIPEI trade show, in Taipei, Taiwan, on June 2, 2026. COMPUTEX TAIPEI is one of the worldâs largest and most significant trade show, featuring products and services related to latest technologies, drones, data solutions, Artificial Intelligence (AI), supercomputers, applications of semiconductors and more from major international tech firms such as Nvidia, Intel and Foxconn. (Photo by Daniel Ceng/Anadolu via Getty Images)

For four years, America's strategy to slow China's AI progress rested on a simple premise: control the silicon, control the outcome. Stop the chips at the border, and the models can't be built.

Washington is now quietly conceding that premise has failed.

The Trump administration's Commerce Department is drafting a new export control rule that would, for the first time, target not the physical movement of chips but remote access to them — blocking Chinese AI firms from renting Nvidia GPU compute through data centers in third countries such as Thailand and Singapore, The Information reported last week. A draft could be circulated to industry groups as early as September.

The shift sounds technical. It is actually an admission: the chip war's physical front has been breached, and the battle is moving to a layer of the stack that U.S. law was never built to police.

The proximate cause is a Chinese startup. In July, Moonshot AI released Kimi K3, a 2.8-trillion-parameter model whose performance came uncomfortably close to leading American systems.

White House Office of Science and Technology Policy director Michael Kratsios publicly alleged that Moonshot trained the model by accessing Nvidia GB300-equipped servers located in Thailand — and that the company had built what he described as a sophisticated internal platform for large-scale distillation of U.S. models, switching between access channels to avoid detection. Moonshot has not publicly responded to the accusations.

Whether or not every claim holds up, the strategic implication does. Chinese hyperscalers — ByteDance, Alibaba and Tencent among them — have reportedly tapped Nvidia compute through data centers in Thailand, Malaysia and Japan.

The export control regime governed where chips could be shipped. It said nothing about who could log into them.

That is the loophole the new rule aims to close. And it is a large one: Nvidia's most advanced silicon may be barred from Chinese soil, but Chinese engineers have been training on it anyway, from a comfortable legal distance.

Here is the problem Washington doesn't want to advertise: it likely lacks the authority to do this.

Export-control lawyers say it is widely acknowledged within the bar that the Commerce Department cannot regulate remote access to chips under existing statute. The fix — the Remote Access Security Act, which would explicitly grant the Bureau of Industry and Security jurisdiction over cloud-based access — passed the House 369–22 in January, then stalled in the Senate Banking Committee.

So the administration is drafting a rule first and hoping the law follows. That sequence matters for anyone who has watched this policy space. The Biden-era AI Diffusion Rule was rescinded in May 2025 and its accompanying due-diligence requirements left unenforced; an earlier attempt at a tiered licensing structure collapsed roughly a week after announcement under industry pushback. U.S. chip policy has become a cycle of ambitious rules, legal gaps, and quiet retreats. Beijing reads that cycle as clearly as anyone in Washington does.

The more durable story may be what is happening without any new rule at all.

Nvidia, facing the threat of statutory action and its own exposure, has begun building a private enforcement apparatus. The company now operates a customer whitelist across Asian markets including Singapore, Malaysia and Japan; the Financial Times reports that more than half of its existing Asian customers were dropped from the approved-buyer list under tightened compliance reviews, with neocloud providers — the firms whose entire business is renting out AI compute — hit hardest. Nvidia employees are reportedly visiting customer data centers in person to verify that facilities are real, servers are installed, and end users check out.

Consider what that means. The most consequential export-control enforcement in the AI era is increasingly being conducted not by customs agents or commerce officials, but by a multi-trillion-dollar company's sales-compliance team. Nvidia has been pushed into the role of border guard for a border that exists in the cloud. That is an awkward position for a company whose CEO said in May that it had "largely conceded" China's AI chip market to Huawei — and it is an unsustainable one for U.S. policy, which now depends on a private firm's incentives aligning with national security, quarter after quarter.

The enforcement net is tightening elsewhere too. This month, Taiwanese prosecutors indicted nine people, including an Nvidia employee and current and former Supermicro associates, over 130 B300-equipped servers falsely declared for use in Taiwan. Seventy-four of those servers made it to China before the rest were intercepted.

In California, prosecutors charged the operators of ALX Solutions with buying more than 200 H100s while declaring fictitious end customers in Singapore and Japan.

The conventional reading of this moment is that Washington closes the loophole, China's AI sector suffocates, and the gap reopens. The evidence points somewhere more complicated.

China's response to the access squeeze has not been to chase the chips harder — it has been to change what the game is. On August 29, one day after the Commerce rule leaked, Tencent open-sourced Hy4-preview, a 770-billion-parameter mixture-of-experts model with a one-million-token context window, free for the world to download. Beijing's Ministry of Commerce, meanwhile, is consulting Alibaba, ByteDance, Zhipu and other domestic firms on adding AI model weights, training data and chip designs to China's own export-control list — a mirror-image weaponization of the same legal machinery Washington built.

Read those moves together. If compute access becomes scarce and contingent, the rational strategy is to make your models efficient enough to train on what you have, open enough to win global adoption anyway, and legally encumbered enough that the world can't simply take them. China's AI majors are executing all three.

With AI expected to sit at the center of next month's U.S.–China summit agenda, the cloud-access rule will likely arrive framed as a tightening. It may function as something else: the moment Washington formally acknowledged that in the AI era, power over technology no longer resides in who owns the hardware — but in who controls the access, the architecture, and increasingly, the terms on which the rest of the world plugs in.

The chip war's first phase was fought at borders and shipping manifests. The next phase will be fought in data-center contracts, compliance APIs, and model licenses. Washington is only just arriving at that battlefield. Beijing, judging by the past two weeks, has been there for some time.

This article was originally published on Forbes.com