An export control gap lets Chinese AI firms access Nvidia Blackwell chips remotely, complicating the first US-China AI safety dialogue of Trump's second term.
- Aivres, Inspur's unlisted U.S. unit, shipped more than $3 billion in Blackwell-equipped servers to Southeast Asian data centers serving Chinese customers.
- U.S. export law targets chip ownership, not remote access - a gap the House-passed Remote Access Security Act has yet to close in the Senate.
- Bessent leads the first formal US-China AI dialogue of Trump's second term in Beijing this month, ahead of a September 24 Trump-Xi summit.
Lead
Aivres, the U.S.-based subsidiary of Chinese tech firm Inspur Group, exported more than $3 billion in computers equipped with Nvidia's (NVDA) most advanced Blackwell chips to Southeast Asian data centers between April 2024 and February 2026, with servers ultimately serving Chinese customers including ByteDance and Alibaba Group (BABA) - a disclosure that arrives days before Treasury Secretary Scott Bessent chairs the first formal US-China AI safety dialogue of Donald Trump's second term in Beijing.
How Are Blacklisted Chinese Firms Accessing Nvidia Chips?
U.S. export controls restrict the physical transfer of advanced semiconductors to Chinese entities but carry no equivalent prohibition on remote access to computing power. That structural gap has been systematically exploited: Chinese AI companies, including several on the Commerce Department's Entity List, route workloads to Nvidia GPU clusters hosted in Thailand, Malaysia, and Japan, paying for access rather than ownership and bypassing license requirements entirely.
Tencent (TCEHY) holds rental contracts worth more than $1.2 billion through Japanese cloud operator Datasection, granting its researchers access to Nvidia B200 processors. ByteDance has secured access to a 36,000-unit Blackwell GPU cluster through a Malaysian cloud operator - a transaction Nvidia confirmed carries no export-control violation under current rules. In July, White House Office of Science and Technology Policy Director Michael Kratsios alleged that Moonshot AI accessed Nvidia GB300 chips at a Thailand facility to train Kimi K3, a 2.8-trillion-parameter open-source model the administration also claims was distilled from Anthropic's frontier system.The Aivres Compliance Gap
Inspur Group was placed on the Entity List in 2023, but its U.S. subsidiary Aivres was not, allowing it to procure and export Blackwell-laden servers legally under existing rules. Total advanced technology exports from Aivres reached at least $5.6 billion over the period examined, of which more than $3 billion consisted of Blackwell-equipped hardware that ultimately served ByteDance and Alibaba. The Commerce Department's Bureau of Industry and Security issued clarifying guidance on May 31, 2026, asserting that export licenses are required when advanced chips flow to any entity whose ultimate parent is headquartered in China or Macau, regardless of where that entity is located. The guidance does not address remote computing access.
What Legislation Could Close the Loophole?
The Remote Access Security Act - RASA - would bring cloud-based access to restricted chips within the scope of U.S. export control authority. The House passed RASA in January 2026; the Senate has not acted. Until statutory authority exists, the BIS cannot directly prohibit a blacklisted Chinese AI firm from accessing a Thailand-based Blackwell cluster. The BIS expanded its regulatory guidance in August and has indicated ongoing scrutiny of overseas data center arrangements, but enforcement against remote-access arrangements requires the legislative backing RASA would provide.
The controversy feeds into broader market dynamics for ai stocks, particularly in the semiconductor supply chain. Nvidia's sales to third-party cloud operators in Southeast Asia do not formally breach export rules, yet those transactions extend Blackwell and Rubin compute to Chinese AI developers at scale - an outcome the controls were designed to prevent.
What Does This Mean for Bessent's Beijing Talks?
The first bilateral AI safety discussions devoted exclusively to artificial intelligence since Trump's return to office are set for mid-September in Beijing, with Bessent leading the U.S. side and Vice Premier He Lifeng expected to anchor the Chinese delegation. The formal agenda covers AI-directed cyberattacks and potential US-China AI lab cooperation on shared risk frameworks - not export controls, which fall under Commerce Department jurisdiction.
The chip-access loophole nonetheless frames the diplomacy. U.S. officials arrive with documented evidence that Chinese frontier AI firms trained models on Nvidia's most advanced silicon through arrangements invisible to the current regulatory framework, even as Bessent has publicly argued that Washington negotiates from a position of technological advantage - noting in May that the U.S. "is in the lead." The Beijing dialogue precedes a Trump-Xi summit on September 24 in Washington, where AI governance is expected alongside trade and Taiwan.
Outlook
The remote-access gap is a statutory problem diplomacy cannot resolve. Legislative momentum behind RASA has stalled in the Senate, BIS guidance has clarified the ownership dimension of controls without touching the access dimension, and commercial incentives for Southeast Asian data center operators to serve Chinese customers remain intact. For Nvidia (NVDA), any future regulatory expansion covering remote computing access carries direct implications for its cloud-operator customer base in the region. The mid-September Beijing dialogue may establish a lasting bilateral channel on AI governance, but the structural loophole enabling blacklisted firms to tap Blackwell compute will persist until Congress acts.





