The AI chip cloud loophole has become a major challenge for US export policy after officials accused Moonshot AI of accessing restricted Nvidia GB300 systems outside China. Kimi K3’s strong performance has intensified debate over remote chip access, export controls and the Remote Access Security Act.
AI chip cloud loophole
US semiconductor restrictions were largely built around controlling exports, re-exports and transfers of advanced hardware. The problem is increasingly that Chinese companies may not need to physically import a restricted chip if they can remotely access computing infrastructure located in another country.
That distinction is now attracting closer scrutiny in Washington. The Bureau of Industry and Security already regulates advanced computing hardware under the Export Administration Regulations, while a 2025 policy statement made clear that some activities involving advanced chips and AI model training can raise licensing concerns.
The policy gap is not simply about smuggling. It is about whether control over a workload should matter as much as the physical location of the machine running it.
Moonshot AI and GB300 access
White House science and technology adviser Michael Kratsios publicly alleged in July that Moonshot AI had obtained servers equipped with Nvidia GB300 chips and had accessed GB300 systems in Thailand, likely for AI training. He also accused the company of using Anthropic technology through large-scale model distillation. Moonshot and Chinese officials disputed the broader allegations.
Nvidia’s GB300 NVL72 is part of the Blackwell Ultra generation and combines 72 Blackwell Ultra GPUs with 36 Grace CPUs in a rack-scale system. It sits well above chips such as the H200, for which the Commerce Department moved in January 2026 to allow case-by-case export licence reviews to China under specific conditions.
Kimi K3 raises the stakes
Moonshot’s Kimi K3 has made the policy debate harder to ignore. The company describes it as a 2.8-trillion-parameter mixture-of-experts model with 104 billion active parameters, a one-million-token context window and 16 of 896 routed experts activated per token. Its technical paper says the model still trails the strongest proprietary systems overall but reaches frontier-level performance across coding, reasoning and agentic tasks.
Independent reporting has also highlighted K3’s strong coding performance, including a top result in a frontend coding benchmark. The significance is not that China has conclusively overtaken the United States, but that high-end Chinese models continue improving despite Washington’s efforts to restrict access to frontier computing hardware.
Remote Access Security Act
Congress is considering a more direct legal response. The House passed the Remote Access Security Act, H.R. 2683, on January 12, 2026. The legislation would expand federal authority to restrict foreign adversaries from remotely accessing controlled US technology, including advanced AI chips through cloud services.
A Senate version, S.3519, was introduced and referred to the Senate Banking Committee on August 5, meaning the proposal has not yet become law.
The difficult part is enforcement. Cloud providers would potentially need stronger systems to determine who ultimately controls a workload, where that customer is located and whether restricted hardware can legally be made available.
Export controls move beyond physical borders
The wider consequence reaches beyond China. Once remote compute itself becomes a regulated export, US policy can affect access to American chips even when those chips never cross a physical border.
That matters for governments and companies building sovereign AI infrastructure around Nvidia hardware in Asia, Europe and the Gulf. The policy question is shifting from “Where is the chip?” to “Who is using it, and for what?”
Kimi K3 has made that shift more urgent. Advanced compute increasingly behaves like a service rather than cargo, while export-control law was designed around physical movement. Washington’s next challenge is deciding whether it can regulate access to computing power without creating a compliance system so broad that it reshapes the global cloud market itself.