
Today's issue is supported by Chartsy
Chartsy turns your Stripe or Paddle data into answers. Ask "show MRR by plan" or "why did churn spike" in plain English and get the chart instantly - no spreadsheets, no pivot tables. Built for founders who'd rather read their numbers than wrestle them.
For two years, America's plan was simple: keep its most powerful AI chips away from China. Whoever controls the chips controls the frontier. Ban the sale, slow the rival.
China found the one gap the ban left open, and it's almost insultingly simple. The rules block selling China the physical chip. They say nothing about China renting one from far away. And for training a model, renting is nearly as good as owning.
So Chinese firms booked time on Nvidia servers sitting in data centers in Thailand, Singapore, and Malaysia, just outside America's reach. They never touched the hardware. They logged in from Beijing. The wall still stood. They walked around it.
The clearest way to see it: three years, three different ways China kept getting the compute the ban was supposed to deny.
How China kept getting frontier compute despite the ban
2024 Smuggling ████████████████ $1B+ chips slipped in
2025 Capped sales ████████ H200s, quota-limited
2026 Cloud renting ██████████████████████ near-unlimitedBars show the relative scale/openness of each route, not identical units. Smuggling: FT estimate of $1B+ in three months. Renting is the hardest to cap nothing crosses a border.
None of these routes are small. By one Epoch AI estimate, somewhere between 290,000 and 1.6 million high-end chip-equivalents were smuggled into China through 2025 and the midpoint of that range alone is roughly a third of all the AI compute China is thought to have. The wall was never watertight. Renting just made climbing it unnecessary.
The ban stops a chip from crossing the border. It says nothing about a Chinese engineer logging into a chip that never moves. America guarded the door. China used the cloud.
Smuggling is a crime. Renting is a login.
Last week we covered the smuggling side of this nine people indicted in Taiwan, including Nvidia and Supermicro insiders, for sneaking 74 banned B300 servers into China with forged documents and a faked website.
It's dramatic. It's also expensive and risky: Chinese buyers reportedly pay around a million dollars per B300 server on the grey market, nearly double the US price, and a CSIS analyst has noted the profit margins on smuggled AI chips rival those in narcotics trafficking.
So the smartest Chinese firms mostly didn't bother. Why smuggle a chip through Indonesia, risk prison, and pay a narco-market premium when you can just rent the same chip legally and log in? Put the two routes side by side and it's obvious why the money moved to the cloud.
Smuggling | |
Legal status | A crime insiders now indicted in Taiwan and the US |
Cost | ~$1M per server, roughly double the US price |
Risk | Seizures at the border, forgery charges, prison |
Traceable? | Yes, a physical chip crosses a border and can be caught |
Renting | |
Legal status | Legal, the ban doesn't mention remote access |
Cost | Standard cloud rates, no smuggler's markup |
Risk | None yet, no law broken |
Traceable? | No, nothing crosses a border to catch |
That's the whole reason this loophole matters more than the smuggling rings grabbing headlines. Smuggling can be policed with customs and indictments. Renting can't - not with the rules as written.
A near-frontier model, trained on rented American machines
Then US officials spotted something alarming. A Chinese startup called Moonshot AI had trained a giant model, Kimi K3, a 2.8-trillion-parameter system that came dangerously close to America's best. According to a senior White House official, it ran on rented Nvidia GB300 servers in Thailand.
The ban had held. Not one banned chip was sold to China. And China caught up anyway.
Then came the twist that makes this bigger than one company. Kimi K3 launched July 16, and around July 27 Moonshot posted its weights to Hugging Face meaning a near-frontier model, allegedly trained on rented American chips, is now free for anyone on earth to download and run.
The loophole didn't just help one Chinese lab catch up. It produced an open model the whole world now holds, including every US startup that quietly builds on it.
3
Countries hosting the rented chips: Thailand, Singapore, Malaysia
2.8T
Parameters in Moonshot's Kimi K3, near the US frontier
369–22
House vote to close the loophole - then the Senate stalled it
Sept
When Washington's new anti-renting rule could reach industry
Keep this honest
The Moonshot claim is a US-government allegation, not an independently confirmed fact. Renting offshore compute is, for now, legal. So the accurate read isn't "China cheated", it's "China found a legal route the ban never covered, and Washington is furious it left the door open."
America opened this door itself
Here's what turns this from a China story into a self-inflicted one. The US had a rule in the works to track who rents these chips overseas, a "know-your-customer" requirement for cloud compute.
Commerce scrapped it. Then Congress tried to close the gap directly: the Remote Access Security Act passed the House 369 to 22. It reached the Senate Banking Committee, and stalled.
What the ban covers | Selling or shipping a physical chip to China - tightly controlled |
What it misses | Renting remote access to a chip that stays in Thailand -untouched |
The rule that would've caught it | Commerce's "know-your-customer" tracking - scrapped before it took effect |
The law that would've closed it | Remote Access Security Act - passed the House 369–22, stalled in the Senate |
What's happening now | Trump's Commerce Dept drafting a rule to block renting; draft could land in September |
So the loophole didn't just exist. America looked straight at it, had two chances to close it, and left it open anyway. Now the Trump administration is racing to draft a fresh rule one that blocks renting, not just buying.
But here's why that's genuinely hard, and why it kept stalling. Blocking a sale means stopping an object at a border, customs officers, shipping manifests, a chip you can physically seize.
Blocking a rental means policing how compute gets used, everywhere, continuously tracking who logs into which data center in which country, forever. That's not a customs problem. It's a global surveillance problem, and nobody has built the machinery for it.
Every month Washington spends designing that machinery, the models keep training. The chip war moved from the factory to the cloud, and the cloud is a much harder place to build a wall.
🔮 The Bottom Line
America spent two years walling off its best AI chips. China didn't climb the wall, it rented a room on the other side and logged in, and trained a near-frontier model on machines America was happy to sell to Thailand.
The ban wasn't wrong. It was aimed at the wrong thing: it controlled the hardware and assumed that controlled the power. In an age when compute is something you rent by the minute from anywhere, what you own matters far less than what you can reach.
That's this week. If you saw the reel and want more like it, our Instagram is @unseen_ainews - breakdowns hit there first, full stories land here. And hit reply with your read: can export controls ever really contain AI, or is this a game Washington can't win?
- hiPreneurs
📧 Forward this to 3 entrepreneur friends who need to see this opportunity












